<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No data can be seen from Forcepoint Firewall in Splunk Enterprise in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/No-data-can-be-seen-from-Forcepoint-Firewall-in-Splunk/m-p/572479#M101315</link>
    <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;Just for the record, we've made progress, whereby we've changed the value of 'LINE_BREAKER = ' from the default '([\r\n]+)' to '&amp;lt;record&amp;gt;' in the $SPLUNK_HOME/etc/system/local/props.conf file, because the indexer could not seem to parse the incoming .xml data, as configured in that format on the Forecepoint SMC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The above was determined from this article:&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Dashboards-Visualizations/How-to-do-event-break-for-XML-file-like-this/m-p/383203" target="_blank"&gt;https://community.splunk.com/t5/Dashboards-Visualizations/How-to-do-event-break-for-XML-file-like-this/m-p/383203&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Now we&amp;nbsp;&lt;STRONG&gt;can&lt;/STRONG&gt; see event data in the Splunk Ent. Web UI &amp;gt; Apps &amp;gt; Forcepoint, which we couldn't before,&amp;nbsp;&lt;STRONG&gt;but&lt;/STRONG&gt; in the Search &amp;amp; Reporting app the event data still cannot seem to be broken into columns if changed to Table view - not sure if that's how data is supposed to be displayed in the first place...&lt;/P&gt;&lt;P&gt;Thanks for your input PickleRick! Much appreciated!&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Lubo&lt;/P&gt;</description>
    <pubDate>Tue, 26 Oct 2021 14:52:10 GMT</pubDate>
    <dc:creator>lzahariev</dc:creator>
    <dc:date>2021-10-26T14:52:10Z</dc:date>
    <item>
      <title>No data can be seen from Forcepoint Firewall in Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-data-can-be-seen-from-Forcepoint-Firewall-in-Splunk/m-p/572199#M101273</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P data-unlink="true"&gt;We've configured a Forcepoint Next Generation Firewall (NGFW) to send data through it's Security Management Center (SMC) after following this article:&amp;nbsp;&lt;A href="https://forcepoint.github.io/docs/ngfw_and_splunk/," target="_blank" rel="noopener"&gt;https://forcepoint.github.io/docs/ngfw_and_splunk/,&lt;/A&gt;&amp;nbsp;however no data is displayed in the Splunk Enterprise (Standalone) Web UI &amp;gt; Apps &amp;gt; Forcepoint. From a 'tcpdump' on the Splunk Ent. device (hosted on Linux CentOS 7), we can see incoming traffic on configured incoming TCP-19997 port.&lt;/P&gt;&lt;P data-unlink="true"&gt;Could anyone advise please?&lt;/P&gt;&lt;P data-unlink="true"&gt;Kind regards,&lt;BR /&gt;Lubo&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk_Ent_webui_screenshot_Forcepoint.PNG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16565iD2C0B5DA8ADF93D1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk_Ent_webui_screenshot_Forcepoint.PNG" alt="Splunk_Ent_webui_screenshot_Forcepoint.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 07:54:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-data-can-be-seen-from-Forcepoint-Firewall-in-Splunk/m-p/572199#M101273</guid>
      <dc:creator>lzahariev</dc:creator>
      <dc:date>2021-10-25T07:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: No data can be seen from Forcepoint Firewall in Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-data-can-be-seen-from-Forcepoint-Firewall-in-Splunk/m-p/572217#M101276</link>
      <description>&lt;P&gt;By "incoming traffic" you mean just SYN packets or full bidirectional flow? Do you see data within this stream? If so, then splunk is receiving the events, you just have to find them.&lt;/P&gt;&lt;P&gt;Are they written to the proper index?&lt;/P&gt;&lt;P&gt;Does this app require any additional configuration to find the events? (might need some macro update or something like that).&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 09:17:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-data-can-be-seen-from-Forcepoint-Firewall-in-Splunk/m-p/572217#M101276</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-25T09:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: No data can be seen from Forcepoint Firewall in Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-data-can-be-seen-from-Forcepoint-Firewall-in-Splunk/m-p/572274#M101281</link>
      <description>&lt;P&gt;Hi, thanks for your reply!&lt;BR /&gt;&lt;BR /&gt;We've had successful three way TCP handshakes between our Forcepoint SMC and Splunk Enterprise (standalone) deployment, however &lt;STRONG&gt;no data that could be seen, as per this screenshot from the deployment guide:&amp;nbsp;&lt;A href="https://forcepoint.github.io/docs/ngfw_and_splunk/media/image9.png" target="_blank"&gt;https://forcepoint.github.io/docs/ngfw_and_splunk/media/image9.png&lt;/A&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;IMG border="0" /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I'm not sure what you meant by "&lt;SPAN&gt;written to the proper index", I'm new to Splunk, however my guess would be that - yes, there is data written to the correct Index, as seen from the Splunk web UI &amp;gt; Settings &amp;gt; Data &amp;gt; Indexes &amp;gt; (name) forcepoint, (app) forcepoint-solutions, (event count) 41.9M, (home path) $SPLUNK_DB/forcepoint/db. We've also created a custom sourcetype - key-value pairs, as per the deployment guide do, mentioned above.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Does this app require any additional configuration to find the events?"&lt;BR /&gt;&amp;nbsp;- Not sure, that's why I was hoping if someone with experience with this type of setup could advise, please.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 13:50:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-data-can-be-seen-from-Forcepoint-Firewall-in-Splunk/m-p/572274#M101281</guid>
      <dc:creator>lzahariev</dc:creator>
      <dc:date>2021-10-25T13:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: No data can be seen from Forcepoint Firewall in Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-data-can-be-seen-from-Forcepoint-Firewall-in-Splunk/m-p/572280#M101283</link>
      <description>&lt;P&gt;Ahh, it seems you're not using the Splunk-provided Add-On which parses the syslog data, but some Forcepoint-supplied solution with a complete docker image containing universal forwarder. Well, that's an ugly solution if you ask me, because you don't know much what's going on inside that docker image.&lt;/P&gt;&lt;P&gt;Your index indeed seems to be populated with events. Check them out with searching simply for&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=forcepoint&lt;/LI-CODE&gt;&lt;P&gt;Unfortunately, there' s not much information about this solution on the Github documentation page so it's best to start with &lt;A href="https://forcepoint.github.io/docs/ngfw_and_splunk/#check-all-components-are-configured-and-running-properly" target="_blank"&gt;https://forcepoint.github.io/docs/ngfw_and_splunk/#check-all-components-are-configured-and-running-properly&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 14:07:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-data-can-be-seen-from-Forcepoint-Firewall-in-Splunk/m-p/572280#M101283</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-25T14:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: No data can be seen from Forcepoint Firewall in Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-data-can-be-seen-from-Forcepoint-Firewall-in-Splunk/m-p/572285#M101286</link>
      <description>&lt;P&gt;A-ha! OK that's better! So I've searched for 'index="forcepoint"' in the Search &amp;amp; Reporting App and&amp;nbsp;&lt;STRONG&gt;can&lt;/STRONG&gt; see data, but it seems bogus, as host=IP.addr.of.SMC, source=tcp:19997, sourcetype=key-value pairs, and that is if I have the Table view selected. If I have the List view selected, I can see more relevant data related what we need...&lt;/P&gt;&lt;P&gt;I have a feeling that we haven't configured Splunk Ent. to break the event data accordingly. The data seems to arrive in a .xml format, as configured on the SMC server:&amp;nbsp;&lt;BR /&gt;SYSLOG_CONF_FILE=&amp;lt;smc_install_dir&amp;gt;/data/fields/syslog_templates/fp-smc-log-fields-v1.xml&lt;/P&gt;&lt;P&gt;I have also changed the sourcetype from 'key-value pairs' to 'syslog', so we'll just have to test and advise back. Alternatively if that doesn't work, I'll try the 'next-generation-firewall' in the sourcetype and give it a second try.&lt;/P&gt;&lt;P&gt;Will let you know, thanks for now!&lt;/P&gt;&lt;P&gt;If you have any other thoughts to share in the meanwhile, please let us know, it would be very much appreciated!&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 14:28:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-data-can-be-seen-from-Forcepoint-Firewall-in-Splunk/m-p/572285#M101286</guid>
      <dc:creator>lzahariev</dc:creator>
      <dc:date>2021-10-25T14:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: No data can be seen from Forcepoint Firewall in Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-data-can-be-seen-from-Forcepoint-Firewall-in-Splunk/m-p/572286#M101287</link>
      <description>&lt;P&gt;Well, configuration on splunk side should not normally be needed since here &lt;A href="https://forcepoint.github.io/docs/ngfw_and_splunk/#setup-forcepoint-app-inside-splunk" target="_blank"&gt;https://forcepoint.github.io/docs/ngfw_and_splunk/#setup-forcepoint-app-inside-splunk&lt;/A&gt; you're coppying an app into splunk's configuration directory so it should contain all appropriate parsing rules. And the UF included in the docker image should set a proper sourcetype/index on forwarded data.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 14:37:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-data-can-be-seen-from-Forcepoint-Firewall-in-Splunk/m-p/572286#M101287</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-25T14:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: No data can be seen from Forcepoint Firewall in Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-data-can-be-seen-from-Forcepoint-Firewall-in-Splunk/m-p/572479#M101315</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;Just for the record, we've made progress, whereby we've changed the value of 'LINE_BREAKER = ' from the default '([\r\n]+)' to '&amp;lt;record&amp;gt;' in the $SPLUNK_HOME/etc/system/local/props.conf file, because the indexer could not seem to parse the incoming .xml data, as configured in that format on the Forecepoint SMC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The above was determined from this article:&lt;BR /&gt;&lt;A href="https://community.splunk.com/t5/Dashboards-Visualizations/How-to-do-event-break-for-XML-file-like-this/m-p/383203" target="_blank"&gt;https://community.splunk.com/t5/Dashboards-Visualizations/How-to-do-event-break-for-XML-file-like-this/m-p/383203&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Now we&amp;nbsp;&lt;STRONG&gt;can&lt;/STRONG&gt; see event data in the Splunk Ent. Web UI &amp;gt; Apps &amp;gt; Forcepoint, which we couldn't before,&amp;nbsp;&lt;STRONG&gt;but&lt;/STRONG&gt; in the Search &amp;amp; Reporting app the event data still cannot seem to be broken into columns if changed to Table view - not sure if that's how data is supposed to be displayed in the first place...&lt;/P&gt;&lt;P&gt;Thanks for your input PickleRick! Much appreciated!&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Lubo&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 14:52:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-data-can-be-seen-from-Forcepoint-Firewall-in-Splunk/m-p/572479#M101315</guid>
      <dc:creator>lzahariev</dc:creator>
      <dc:date>2021-10-26T14:52:10Z</dc:date>
    </item>
  </channel>
</rss>

