<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SPLUNK for SNORT not working in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SPLUNK-for-SNORT-not-working/m-p/86348#M5563</link>
    <description>&lt;P&gt;&lt;A href="http://www.disects.com/whitepapers/Logging_Snort_alerts_to_Syslog_and_Splunk.pdf"&gt;http://www.disects.com/whitepapers/Logging_Snort_alerts_to_Syslog_and_Splunk.pdf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 06 Oct 2013 03:55:47 GMT</pubDate>
    <dc:creator>praveen_recker</dc:creator>
    <dc:date>2013-10-06T03:55:47Z</dc:date>
    <item>
      <title>SPLUNK for SNORT not working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SPLUNK-for-SNORT-not-working/m-p/86345#M5560</link>
      <description>&lt;P&gt;I am trying to get SPLUNK for SNORT up and running with no luck. I am new to SNORT,SPLUNK, and linux in gerneral. But here is what i have.&lt;BR /&gt;
CentOS running SNORT and producing an ALERT and log file&lt;BR /&gt;
Windows PC running SPLUNK&lt;/P&gt;

&lt;P&gt;I setup the universal forwarder and all my SNORT alerts appear in SPLUNK as sourcetype snort_alert_full using the following command:&lt;BR /&gt;
/opt/splunkforwarder/bin/splunk add monitor /etc/log/snort/ -index main -sourcetype snort_alert_full&lt;/P&gt;

&lt;P&gt;When viewing in Splunk for snort i have no results. my understanding is that when the data is processed it should be renames from snort_alert_full to snort, i dont see this happeneing. And cannot search for src_ip as it is not being indexed properly.&lt;/P&gt;

&lt;P&gt;Is there something i have to do to get Splunk for snort to process the data and index it properly?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:16:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SPLUNK-for-SNORT-not-working/m-p/86345#M5560</guid>
      <dc:creator>thunbolt22</dc:creator>
      <dc:date>2020-09-28T14:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK for SNORT not working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SPLUNK-for-SNORT-not-working/m-p/86346#M5561</link>
      <description>&lt;P&gt;Try changing snort to alert fast. Then same for the file monitor for the splunk forwarder&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jul 2013 12:54:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SPLUNK-for-SNORT-not-working/m-p/86346#M5561</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2013-07-06T12:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK for SNORT not working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SPLUNK-for-SNORT-not-working/m-p/86347#M5562</link>
      <description>&lt;P&gt;I ended up reinstalling Splunk for Snort and everything worked. &lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2013 13:23:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SPLUNK-for-SNORT-not-working/m-p/86347#M5562</guid>
      <dc:creator>thunbolt22</dc:creator>
      <dc:date>2013-07-08T13:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK for SNORT not working</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SPLUNK-for-SNORT-not-working/m-p/86348#M5563</link>
      <description>&lt;P&gt;&lt;A href="http://www.disects.com/whitepapers/Logging_Snort_alerts_to_Syslog_and_Splunk.pdf"&gt;http://www.disects.com/whitepapers/Logging_Snort_alerts_to_Syslog_and_Splunk.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Oct 2013 03:55:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SPLUNK-for-SNORT-not-working/m-p/86348#M5563</guid>
      <dc:creator>praveen_recker</dc:creator>
      <dc:date>2013-10-06T03:55:47Z</dc:date>
    </item>
  </channel>
</rss>

