<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't Extract CEF Fields in Distributed Environment in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630961#M108149</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/7809"&gt;@aferone&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;check the sourcetype assigned in your input and verify if it's the same requested in TA's props.conf.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 15 Feb 2023 13:40:29 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-02-15T13:40:29Z</dc:date>
    <item>
      <title>Can't Extract CEF Fields in Distributed Environment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630957#M108146</link>
      <description>&lt;P&gt;Hello to all.&lt;BR /&gt;&lt;BR /&gt;I am using the CEF Extraction TA for extracting CEF fields in a FireEye log.&amp;nbsp; When I test this on a standalone system with Indexer and Search Head, the cs#Label fields extract correctly.&lt;BR /&gt;&lt;BR /&gt;As soon as I put this in an environment with a Heavy Forwarder, Indexer, and Search Head distributed (or even just Indexer and Search Head)., the fields will not extract.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am at my wit's end here.&lt;BR /&gt;&lt;BR /&gt;Help?&amp;nbsp; Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 13:34:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630957#M108146</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2023-02-15T13:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Extract CEF Fields in Distributed Environment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630959#M108147</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/7809"&gt;@aferone&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;where did you&amp;nbsp; install the TA?&lt;/P&gt;&lt;P&gt;You have to mandatory install it on HF and SH, I usually install it also on Indexers but it isn't mandatory (as the others).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 13:36:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630959#M108147</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-15T13:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Extract CEF Fields in Distributed Environment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630960#M108148</link>
      <description>&lt;P&gt;Hello Giuseppe,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Yes, it is currently installed on all 3, actually.&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 13:38:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630960#M108148</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2023-02-15T13:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Extract CEF Fields in Distributed Environment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630961#M108149</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/7809"&gt;@aferone&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;check the sourcetype assigned in your input and verify if it's the same requested in TA's props.conf.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 13:40:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630961#M108149</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-15T13:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Extract CEF Fields in Distributed Environment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630962#M108150</link>
      <description>&lt;P&gt;I actually copied the props and transforms stanzas from the TA and applied them to the sourcetype in which we need to extract from.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 13:41:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630962#M108150</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2023-02-15T13:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Extract CEF Fields in Distributed Environment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630965#M108152</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/7809"&gt;@aferone&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that you assigned the "cefevents" sourcetype to your input.&lt;/P&gt;&lt;P&gt;Why aren't you using the TA, only adding the inputs.conf?&lt;/P&gt;&lt;P&gt;Then, You said that youìre using this TA for FireEye, did you explored the dedicated TA for FireEye (&lt;A href="https://splunkbase.splunk.com/app/1904)?" target="_blank"&gt;https://splunkbase.splunk.com/app/1904)?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;There are some restrictions:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;When you should not use this TA:

This Technology Add-on (TA) is not necessary for simple Splunk installations (e.g. Single Splunk install -- no forwarders or separate indexers)

Instead just install the app located here: https://apps.splunk.com/app/1845

When you should use this TA:

This TA supports the FireEye_v3 app. It does not contain any dashboards and should be installed on Splunk indexers while the app itself installed on the search head.&lt;/LI-CODE&gt;&lt;P&gt;but maybe it's better for your distributed environment.&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 13:49:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630965#M108152</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-15T13:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Extract CEF Fields in Distributed Environment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630966#M108153</link>
      <description>&lt;P&gt;Surprisingly, the FireEye TA will extract the CEF headers but not the other cs#Label fields.&amp;nbsp; This is why we are going down this road. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 13:51:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630966#M108153</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2023-02-15T13:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Extract CEF Fields in Distributed Environment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630967#M108154</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/7809"&gt;@aferone&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;really strange!&lt;/P&gt;&lt;P&gt;anyway,&amp;nbsp;I suppose that you assigned the "cefevents" sourcetype to your input.&lt;/P&gt;&lt;P&gt;Why aren't you using the TA, only adding the inputs.conf, instead taking props.conmf and transforms.conf?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 13:56:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630967#M108154</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-15T13:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Extract CEF Fields in Distributed Environment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630969#M108155</link>
      <description>&lt;P&gt;Because we don't want to assign FireEye events to a sourcetype of "cefevents".&amp;nbsp; "cefevents" is too broad and doesn't mean anything.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 13:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630969#M108155</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2023-02-15T13:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Extract CEF Fields in Distributed Environment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630970#M108156</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/7809"&gt;@aferone&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Ok, correct.&lt;/P&gt;&lt;P&gt;I suppose that you created a new add-on with a different sourcetype and you deployed this TA to all machines.&lt;/P&gt;&lt;P&gt;what's the sourcetype of the events not correctly parsed?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 14:00:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630970#M108156</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-15T14:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Extract CEF Fields in Distributed Environment</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630977#M108159</link>
      <description>&lt;P&gt;I'm starting to wonder if the FIreEye TA, which also has "hx_cef_syslog", is conflicting because that is also installed.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 14:50:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-t-Extract-CEF-Fields-in-Distributed-Environment/m-p/630977#M108159</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2023-02-15T14:50:04Z</dc:date>
    </item>
  </channel>
</rss>

