<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configuring EdgeRouter Syslog for HomeMonitor - unable to parse data cleanly in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-EdgeRouter-Syslog-for-HomeMonitor-unable-to-parse/m-p/534064#M64502</link>
    <description>&lt;P&gt;My goal - my ISP has warned me I've got a security issue. I'm trying to monitor my outgoing data to see which device is possibly speaking to the enemy.&lt;/P&gt;&lt;P&gt;HomeMonitor looks pretty well suited to this task.&amp;nbsp; I've got it all installed, but am struggling to get the sourcetype configured for the Edge Router syslog format.&lt;/P&gt;&lt;P&gt;My route&lt;SPAN&gt;r is a Ubiquiti EdgeRouter X.&amp;nbsp;My Splunk Server is a Win 10 PC, hardwired into EdgeRouter.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I configured the edgerouter to turn on syslogging, &amp;amp; enabled logging for the NAT masquarade. This gives me logs of all outgoing traffic only. I am able to pull the UDS traffic using Kiwi Syslog, it spits it out in this format:&lt;/P&gt;&lt;P&gt;2020-12-23 18:21:54 Kernel.Warning 192.168.2.1 Dec 23 18:21:55 ubnt kernel: [NAT-5010-MASQ] IN= OUT=eth0 src=XX.XX.XXX.XXX DST=XX.XX.XXX.X LEN=73 TOS=0x00 PREC=0x00 TTL=64 ID=14664 DF PROTO=UDP SPT=21167 DPT=53 LEN=53&lt;/P&gt;&lt;P&gt;Per Ubiquiti's website,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt;&lt;SPAN&gt;EdgeOS uses the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;BSD&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;Syslog format, the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;rsyslogd&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;service and UDP port 514 (not customizable) for Syslog by default.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried installing this TA, but it appears to me misconfigured for my purposes.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/3483/" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/3483/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I read elsewhere that using asus sourcetype gets it close. I cloned asus sourcetype &amp;amp; made a few changes to it, dst &amp;amp; dpt weren't capatilized (I'm assuming it's case sensitive), I updated time format. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This gets me SOME data, in Network Overview Outbound Traffic, but it only shows Source IPs. I really want to look at destination IPs &amp;amp; see if they're on a blacklist etc...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I think the blocked traffic &amp;amp; map of connections panels are more suited to this task, but I'm not getting any data populating in there.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any guidance? I assume I'm missing some critical data alias' or something.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All help is appreciated, here's a pic of the sourcetype config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EdgeRouter Config.png" style="width: 522px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12360i5D9E88CF1DDE4D30/image-size/large?v=v2&amp;amp;px=999" role="button" title="EdgeRouter Config.png" alt="EdgeRouter Config.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Dec 2020 16:25:06 GMT</pubDate>
    <dc:creator>LargeCanineUnit</dc:creator>
    <dc:date>2020-12-24T16:25:06Z</dc:date>
    <item>
      <title>Configuring EdgeRouter Syslog for HomeMonitor - unable to parse data cleanly</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-EdgeRouter-Syslog-for-HomeMonitor-unable-to-parse/m-p/534064#M64502</link>
      <description>&lt;P&gt;My goal - my ISP has warned me I've got a security issue. I'm trying to monitor my outgoing data to see which device is possibly speaking to the enemy.&lt;/P&gt;&lt;P&gt;HomeMonitor looks pretty well suited to this task.&amp;nbsp; I've got it all installed, but am struggling to get the sourcetype configured for the Edge Router syslog format.&lt;/P&gt;&lt;P&gt;My route&lt;SPAN&gt;r is a Ubiquiti EdgeRouter X.&amp;nbsp;My Splunk Server is a Win 10 PC, hardwired into EdgeRouter.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I configured the edgerouter to turn on syslogging, &amp;amp; enabled logging for the NAT masquarade. This gives me logs of all outgoing traffic only. I am able to pull the UDS traffic using Kiwi Syslog, it spits it out in this format:&lt;/P&gt;&lt;P&gt;2020-12-23 18:21:54 Kernel.Warning 192.168.2.1 Dec 23 18:21:55 ubnt kernel: [NAT-5010-MASQ] IN= OUT=eth0 src=XX.XX.XXX.XXX DST=XX.XX.XXX.X LEN=73 TOS=0x00 PREC=0x00 TTL=64 ID=14664 DF PROTO=UDP SPT=21167 DPT=53 LEN=53&lt;/P&gt;&lt;P&gt;Per Ubiquiti's website,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt;&lt;SPAN&gt;EdgeOS uses the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;BSD&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;Syslog format, the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;rsyslogd&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;service and UDP port 514 (not customizable) for Syslog by default.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried installing this TA, but it appears to me misconfigured for my purposes.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/3483/" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/3483/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I read elsewhere that using asus sourcetype gets it close. I cloned asus sourcetype &amp;amp; made a few changes to it, dst &amp;amp; dpt weren't capatilized (I'm assuming it's case sensitive), I updated time format. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This gets me SOME data, in Network Overview Outbound Traffic, but it only shows Source IPs. I really want to look at destination IPs &amp;amp; see if they're on a blacklist etc...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I think the blocked traffic &amp;amp; map of connections panels are more suited to this task, but I'm not getting any data populating in there.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any guidance? I assume I'm missing some critical data alias' or something.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All help is appreciated, here's a pic of the sourcetype config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EdgeRouter Config.png" style="width: 522px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12360i5D9E88CF1DDE4D30/image-size/large?v=v2&amp;amp;px=999" role="button" title="EdgeRouter Config.png" alt="EdgeRouter Config.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2020 16:25:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-EdgeRouter-Syslog-for-HomeMonitor-unable-to-parse/m-p/534064#M64502</guid>
      <dc:creator>LargeCanineUnit</dc:creator>
      <dc:date>2020-12-24T16:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring EdgeRouter Syslog for HomeMonitor - unable to parse data cleanly</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-EdgeRouter-Syslog-for-HomeMonitor-unable-to-parse/m-p/534088#M64506</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229988"&gt;@LargeCanineUnit&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know your dashboard search but I would try to add dest field as an alias.&lt;/P&gt;&lt;P&gt;FIELDALIAS-dest = DST as dest&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;İf this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Dec 2020 05:17:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-EdgeRouter-Syslog-for-HomeMonitor-unable-to-parse/m-p/534088#M64506</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2020-12-25T05:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring EdgeRouter Syslog for HomeMonitor - unable to parse data cleanly</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-EdgeRouter-Syslog-for-HomeMonitor-unable-to-parse/m-p/534587#M64534</link>
      <description>&lt;P&gt;My main issue ended up being a mess of typos, I had several underscores instead of hyphens, and FILEDALIAS instead of FIELDALIAS. Fixing those typos has, for the most part, corrected the issue.&lt;/P&gt;&lt;P&gt;I was able to build up a dashboard of what I needed with this search term:&lt;/P&gt;&lt;P&gt;index=homemonitor sourcetype=$sourcetype$ direction=out | iplocation dest_ip | stats sparkline count by dest_ip, src_ip, Country, City | sort -count&lt;/P&gt;&lt;P&gt;This lets me see which internal IP on my network is talking to suspicious locations.&lt;/P&gt;&lt;P&gt;Certainly not efficient, but it should give me something to go on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Dec 2020 21:55:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Configuring-EdgeRouter-Syslog-for-HomeMonitor-unable-to-parse/m-p/534587#M64534</guid>
      <dc:creator>LargeCanineUnit</dc:creator>
      <dc:date>2020-12-31T21:55:39Z</dc:date>
    </item>
  </channel>
</rss>

