<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I install the Splunk App for Secret Server? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445267#M54792</link>
    <description>&lt;P&gt;hi @jaxjohnny2000,&lt;/P&gt;

&lt;P&gt;Thanks for posting on Splunk answers. Could you give us some more context on your problem? The more detail your post contains, the better chance it has being answered by the community.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Sep 2018 22:54:41 GMT</pubDate>
    <dc:creator>mstjohn_splunk</dc:creator>
    <dc:date>2018-09-06T22:54:41Z</dc:date>
    <item>
      <title>How do I install the Splunk App for Secret Server?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445266#M54791</link>
      <description>&lt;P&gt;We are going to use syslog-ng and a heavy forwarder for the SecretServer.  Could it be that we only need to change the props.conf in the SecretServer app to [SecrectServer] rather than the default [syslog] stanza? &lt;/P&gt;

&lt;P&gt;The app is designed to have the SecretServer sent directly to an Indexer. However, we are first sending it to a syslog-ng and then then via Heavy Forwarder to the index cluster. Therefore, all the panels are setup to use "source=secretserver". &lt;/P&gt;

&lt;P&gt;But, when the syslog server sends the data, the source is the LOG file. So, should we install this app on the indexers, forwarders, and search heads; or just the search heads? Then, the source will change, as the log files rotate. So, we can use sourcetype to power all the panels. Should we then update the props.conf file with the sourcetype stanza, SecretServer? &lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 14:56:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445266#M54791</guid>
      <dc:creator>jaxjohnny2000</dc:creator>
      <dc:date>2018-09-06T14:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: How do I install the Splunk App for Secret Server?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445267#M54792</link>
      <description>&lt;P&gt;hi @jaxjohnny2000,&lt;/P&gt;

&lt;P&gt;Thanks for posting on Splunk answers. Could you give us some more context on your problem? The more detail your post contains, the better chance it has being answered by the community.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 22:54:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445267#M54792</guid>
      <dc:creator>mstjohn_splunk</dc:creator>
      <dc:date>2018-09-06T22:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: How do I install the Splunk App for Secret Server?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445268#M54793</link>
      <description>&lt;P&gt;The app is designed to have the Secret server sent directly to an Indexer.  However, we are first sending it to a syslog-ng and then then via Heavy Forwarder to the index cluster.  Therefore all the panels are setup to use "source=secretserver".  But when the syslog server sends the data, the source is the LOG file.  So, should we install this app on the indexers, forwarders, and search heads; or just the search heads.  Then, the source will change, as the log files rotate.  So we can use sourcetype to power all the panels.  Should we then update the props.conf file with the sourcetype stanza, secretserver? &lt;/P&gt;</description>
      <pubDate>Fri, 07 Sep 2018 11:47:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445268#M54793</guid>
      <dc:creator>jaxjohnny2000</dc:creator>
      <dc:date>2018-09-07T11:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: How do I install the Splunk App for Secret Server?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445269#M54794</link>
      <description>&lt;P&gt;Is the data already present in Splunk or you trying to get data into Splunk? If the data is already available then you can use the prebuilt dashboards and saved searches present in the app.  All you need to do is edit the saved searches accordingly. This app just need to be on the search head.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2018 00:56:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445269#M54794</guid>
      <dc:creator>Rob2520</dc:creator>
      <dc:date>2018-09-08T00:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: How do I install the Splunk App for Secret Server?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445270#M54795</link>
      <description>&lt;P&gt;Thank you.  However, there are no pre-built panels on the Secret server app. &lt;/P&gt;

&lt;P&gt;The application is working now.  I modified the props.conf with the sourcetype and then modified all the xml panels switching source with sourcetype in the search and finally the eventtypes.conf to change to searching by sourcetype. &lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 11:28:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445270#M54795</guid>
      <dc:creator>jaxjohnny2000</dc:creator>
      <dc:date>2018-09-10T11:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: How do I install the Splunk App for Secret Server?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445271#M54796</link>
      <description>&lt;P&gt;@jaxjohnny2000,&lt;/P&gt;

&lt;P&gt;Thanks for providing more info. I moved your comment up to the main post so that it's more visible.&lt;/P&gt;

&lt;P&gt;Good luck with your query!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 16:38:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445271#M54796</guid>
      <dc:creator>mstjohn_splunk</dc:creator>
      <dc:date>2018-09-11T16:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: How do I install the Splunk App for Secret Server?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445272#M54797</link>
      <description>&lt;P&gt;yes the data is getting into splunk.  however, the fields are not really being extracted properly.  &lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 19:01:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445272#M54797</guid>
      <dc:creator>jaxjohnny2000</dc:creator>
      <dc:date>2018-11-14T19:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: How do I install the Splunk App for Secret Server?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445273#M54798</link>
      <description>&lt;P&gt;@jaxjohnny2000 Did you ever get the additional fields to extract properly? &lt;/P&gt;

&lt;P&gt;Running into the same issues, edited props.conf to look at proper Eventtype but some of the fields are still not extracting properly. For example, Action, By_User and plenty of others.  The regex appears to be correct and when tested with rubular as well as the splunk custom field extractor we get the expected results, but they do not carry over into search... &lt;/P&gt;</description>
      <pubDate>Tue, 18 Dec 2018 20:45:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445273#M54798</guid>
      <dc:creator>gstefancyk</dc:creator>
      <dc:date>2018-12-18T20:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: How do I install the Splunk App for Secret Server?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445274#M54799</link>
      <description>&lt;P&gt;So are you receiving data at all?  If so, check the sourcetype.  I had to remove the syslog stanza completely.&lt;BR /&gt;&lt;BR /&gt;
I have a Syslog-ng listening and then sending to the index cluster sourcetype=secretserver&lt;/P&gt;

&lt;P&gt;Then I checked the case of the stanza (does that matter?)&lt;/P&gt;

&lt;P&gt;[secretserver]&lt;BR /&gt;
EXTRACT-EventID = (?i)^(?:[^|]*|){4}(?P[^|]+)&lt;BR /&gt;
EXTRACT-action = (Action: (?P[[^:]]+]) )&lt;BR /&gt;
EXTRACT-body = ^([^|]+|){7}(?P[^|]+)&lt;BR /&gt;
EXTRACT-by_user = (By User: (?P(&lt;A href="https://community.splunk.com/?!Item%20Name:" target="_blank"&gt;^:=&lt;/A&gt;)+) )&lt;BR /&gt;
EXTRACT-container_name = (Container Name: (?P[^:=]+(?!suid=)) )&lt;BR /&gt;
EXTRACT-details = (Details: (?P[^:]+) (suid=))&lt;BR /&gt;
EXTRACT-event = (Event: (?P[^:]+) )&lt;BR /&gt;
EXTRACT-file_id = (fileId=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-file_name = (fname=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-file_type = (fileType=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-full_suser = (?i) suser=(?P.+?)\s\S+=&lt;BR /&gt;
EXTRACT-item_name = (Item Name: (?P[^:=]+(?!suid=)) )&lt;BR /&gt;
EXTRACT-log_level = ^([^|]+|){6}(?P[^|]+)&lt;BR /&gt;
EXTRACT-message_name = ^([^|]+|){5}(?P[^|]+)&lt;BR /&gt;
EXTRACT-preamble = ^(?P[^|]+)|&lt;BR /&gt;
EXTRACT-product = ^([^|]+|){2}(?P[^|]+)&lt;BR /&gt;
EXTRACT-receipt_time = (rt=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-tss_cs1 = (cs1=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-tss_cs1Label = (cs1Label=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-tss_cs2 = (cs2=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-tss_cs2Label = (cs2Label=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-tss_cs3 = (cs3=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-tss_cs3Label = (cs3Label=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-tss_cs4 = (cs4=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-tss_cs4Label = (cs4Label=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-tss_msg = (msg=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-tss_signature_id = ^([^|]+|){4}(?P[^|]+)&lt;BR /&gt;
EXTRACT-tss_src = (src=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-tss_suid = (suid=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-tss_suser = (suser=(?P[^=]+) )&lt;BR /&gt;
EXTRACT-vendor = ^([^|]+|){1}(?P[^|]+)&lt;BR /&gt;
EXTRACT-version = ^([^|]+|){3}(?P[^|]+)&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_1 = EventID AS signature_id&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_10 = action AS change_type&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_11 = tss_cs1 AS cs1&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_12 = tss_cs2 AS cs2&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_13 = tss_cs3 AS cs3&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_14 = tss_cs4 AS cs4&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_15 = tss_cs4Label AS cs4Label&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_16 = tss_cs3Label AS cs3Label&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_17 = tss_cs2Label AS cs2Label&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_18 = tss_cs1Label AS cs1Label&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_19 = tss_msg AS msg&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_2 = product AS vendor_product&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_20 = tss_signature_id AS signature_id&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_3 = product AS app&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_4 = log_level AS severity&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_5 = suser AS src_user&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_6 = suser AS user&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_7 = duser AS object&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_8 = duid AS object_id&lt;BR /&gt;
FIELDALIAS-aob_gen_syslog_alias_9 = container_name AS dest&lt;BR /&gt;
SHOULD_LINEMERGE = 0&lt;BR /&gt;
pulldown_type = 1&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:30:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-install-the-Splunk-App-for-Secret-Server/m-p/445274#M54799</guid>
      <dc:creator>jaxjohnny2000</dc:creator>
      <dc:date>2020-09-29T22:30:40Z</dc:date>
    </item>
  </channel>
</rss>

