<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Linux Netfilter(iptables) technology add-on: How to collect logs from iptables? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Linux-Netfilter-iptables-technology-add-on-How-to-collect-logs/m-p/373370#M45238</link>
    <description>&lt;P&gt;Hi&lt;BR /&gt;
Can you help me with some questions?&lt;/P&gt;

&lt;P&gt;If I understand, this add-on parsing iptables logs, but first I need to change config of ipatables to log in to separate file?&lt;BR /&gt;
There is no any inputs.conf or something like it. I don't know how to use this add-on even with &lt;A href="https://github.com/doksu/TA_netfilter/wiki#enterprise-security"&gt;documentation&lt;/A&gt;. &lt;/P&gt;</description>
    <pubDate>Mon, 12 Feb 2018 15:33:33 GMT</pubDate>
    <dc:creator>test_qweqwe</dc:creator>
    <dc:date>2018-02-12T15:33:33Z</dc:date>
    <item>
      <title>Linux Netfilter(iptables) technology add-on: How to collect logs from iptables?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Linux-Netfilter-iptables-technology-add-on-How-to-collect-logs/m-p/373370#M45238</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
Can you help me with some questions?&lt;/P&gt;

&lt;P&gt;If I understand, this add-on parsing iptables logs, but first I need to change config of ipatables to log in to separate file?&lt;BR /&gt;
There is no any inputs.conf or something like it. I don't know how to use this add-on even with &lt;A href="https://github.com/doksu/TA_netfilter/wiki#enterprise-security"&gt;documentation&lt;/A&gt;. &lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2018 15:33:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Linux-Netfilter-iptables-technology-add-on-How-to-collect-logs/m-p/373370#M45238</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2018-02-12T15:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: Linux Netfilter(iptables) technology add-on: How to collect logs from iptables?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Linux-Netfilter-iptables-technology-add-on-How-to-collect-logs/m-p/373371#M45239</link>
      <description>&lt;P&gt;Assuming you're running splunk(forwarder) on the same box as where you want to capture the iptables logs, you'll need to:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Enable and configure logging in iptables (refer to iptables docs / online guides etc. for details; first hit on google: &lt;A href="https://www.thegeekstuff.com/2012/08/iptables-log-packets/?utm_source=feedburner"&gt;https://www.thegeekstuff.com/2012/08/iptables-log-packets/?utm_source=feedburner&lt;/A&gt;)&lt;/LI&gt;
&lt;LI&gt;Configure the system's syslog daemon to write the iptables log to a suitable file (or at least confirm where it writes by default)&lt;/LI&gt;
&lt;LI&gt;Configure splunk with a file monitor input to read the respective file. I understand from the TA doc you can use the syslog sourcetype, which will be transformed to linux:netfilter by the TA.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 12 Feb 2018 15:56:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Linux-Netfilter-iptables-technology-add-on-How-to-collect-logs/m-p/373371#M45239</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-02-12T15:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: Linux Netfilter(iptables) technology add-on: How to collect logs from iptables?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Linux-Netfilter-iptables-technology-add-on-How-to-collect-logs/m-p/373372#M45240</link>
      <description>&lt;P&gt;You could split the netfilter (iptables) events into their own file then in the inputs.conf monitor stanza for that file specify the sourcetype of linux:netfilter, but I designed the app so that doing so is not necessary. If you simply ingest the netfilter events mixed with other syslogged events (e.g. /var/log/messages) and that file is ingested with sourcetype "syslog", then the app will automatically change the sourcetype of just the netfilter events to linux:netfilter.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2018 02:24:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Linux-Netfilter-iptables-technology-add-on-How-to-collect-logs/m-p/373372#M45240</guid>
      <dc:creator>doksu</dc:creator>
      <dc:date>2018-02-14T02:24:38Z</dc:date>
    </item>
  </channel>
</rss>

