<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Snort output format expected for built-in Snort source type in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Snort-output-format-expected-for-built-in-Snort-source-type/m-p/508426#M62437</link>
    <description>&lt;P&gt;I'm using Splunk Enterprise 8.0.4.1. I'm looking to upload Snort logs (version 2.9.16) manually (via Settings -- Add Data).&lt;/P&gt;&lt;P&gt;I see there is a Source Type under Network &amp;amp; Security for Snort. However, I can't tell which Snort output type it expects.&lt;/P&gt;&lt;P&gt;I tried the following output formats, but none were interpreted correctly:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;alert_fast&lt;/LI&gt;&lt;LI&gt;alert_full&lt;/LI&gt;&lt;LI&gt;alert_csv&lt;/LI&gt;&lt;LI&gt;unified2&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Note: I am not using the Snort for Splunk nor the Splunk for Snort apps. I am attempting to use the built-in source type.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jul 2020 03:15:56 GMT</pubDate>
    <dc:creator>Zaphod</dc:creator>
    <dc:date>2020-07-10T03:15:56Z</dc:date>
    <item>
      <title>Snort output format expected for built-in Snort source type</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Snort-output-format-expected-for-built-in-Snort-source-type/m-p/508426#M62437</link>
      <description>&lt;P&gt;I'm using Splunk Enterprise 8.0.4.1. I'm looking to upload Snort logs (version 2.9.16) manually (via Settings -- Add Data).&lt;/P&gt;&lt;P&gt;I see there is a Source Type under Network &amp;amp; Security for Snort. However, I can't tell which Snort output type it expects.&lt;/P&gt;&lt;P&gt;I tried the following output formats, but none were interpreted correctly:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;alert_fast&lt;/LI&gt;&lt;LI&gt;alert_full&lt;/LI&gt;&lt;LI&gt;alert_csv&lt;/LI&gt;&lt;LI&gt;unified2&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Note: I am not using the Snort for Splunk nor the Splunk for Snort apps. I am attempting to use the built-in source type.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 03:15:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Snort-output-format-expected-for-built-in-Snort-source-type/m-p/508426#M62437</guid>
      <dc:creator>Zaphod</dc:creator>
      <dc:date>2020-07-10T03:15:56Z</dc:date>
    </item>
  </channel>
</rss>

