<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Barracuda Email Gateway Add-on Field Extraction not Extracting in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Barracuda-Email-Gateway-Add-on-Field-Extraction-not-Extracting/m-p/683496#M114092</link>
    <description>&lt;P&gt;Hey thanks for the reply!&lt;/P&gt;&lt;P&gt;Honestly, I forgot about this post or I would have updated it. It seems like the add-on is for a different version of the Barracuda Email Defense than we have. The Barracuda syslog documentation shows a log format that is different than what our cloud platform is sending, but does match what this add-on is looking for. I believe the add-on may be for a self-hosted or on-prem solution.&lt;/P&gt;&lt;P&gt;I was able to parse our logs by a field extraction spath on the extracted JSON. Unfortunately, nothing in the logs easily indicates email directionality, so that's a pain.&lt;/P&gt;</description>
    <pubDate>Sat, 06 Apr 2024 20:54:04 GMT</pubDate>
    <dc:creator>BoxerguyT89</dc:creator>
    <dc:date>2024-04-06T20:54:04Z</dc:date>
    <item>
      <title>Barracuda Email Gateway Add-on Field Extraction not Extracting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Barracuda-Email-Gateway-Add-on-Field-Extraction-not-Extracting/m-p/678016#M113314</link>
      <description>&lt;P&gt;Hello all I hope this is the right forum,&lt;/P&gt;&lt;P&gt;I am having some trouble with the Barracuda Email Security Gateway Add-on and field extraction.&lt;/P&gt;&lt;P&gt;We have a Splunk Cloud subscription and I am using an Ubuntu server with rsyslog and a universal forwarder to send syslog data to our Splunk Cloud instance.&lt;/P&gt;&lt;P&gt;I have the Barracuda Email Security Gateway Add-on installed in our Splunk Cloud.&lt;/P&gt;&lt;P&gt;I have the data from our Barracuda Email Gateway system going into a folder called /var/log/syslog_barracuda.log.&lt;/P&gt;&lt;P&gt;I have my inputs.conf file configured as follows:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///var/log/syslog_barracuda.log]
disabled = 0
sourcetype = barracuda&lt;/LI-CODE&gt;&lt;P&gt;In our Splunk Cloud, I see the events, and they have the "barracuda" sourcetype as expected.&lt;/P&gt;&lt;P&gt;The problem is, no field extraction is applied to these events.&lt;/P&gt;&lt;P&gt;Is there something I am missing? The Add-on only shows to add the lines to the inputs.conf file.&lt;/P&gt;&lt;P&gt;Any help would be appreciated, I am new to Splunk and trying to wrap my head around everything.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2024 21:26:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Barracuda-Email-Gateway-Add-on-Field-Extraction-not-Extracting/m-p/678016#M113314</guid>
      <dc:creator>BoxerguyT89</dc:creator>
      <dc:date>2024-02-19T21:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: Barracuda Email Gateway Add-on Field Extraction not Extracting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Barracuda-Email-Gateway-Add-on-Field-Extraction-not-Extracting/m-p/683494#M114091</link>
      <description>&lt;P&gt;It appears you have set this addon up correctly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have other sourcetypes like "barracuda_scan", "barracuda_recv", or "barracuda_send"? This addon appears to intake the "barracuda" sourcetype, then use transforms to change the sourcetype to barracuda_&amp;lt;type&amp;gt; and then those other sourcetypes would then have fields extractions.&lt;/P&gt;&lt;P&gt;If you have logs with the sourcetype "barracuda" but match the regex: "\d{10}\s\d{10}\sRECV" (a ten-digit number, then a space, then a ten-digit number, then the word "RECV"), then that would mean something is not working with the transform.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2024 20:42:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Barracuda-Email-Gateway-Add-on-Field-Extraction-not-Extracting/m-p/683494#M114091</guid>
      <dc:creator>marnall</dc:creator>
      <dc:date>2024-04-06T20:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: Barracuda Email Gateway Add-on Field Extraction not Extracting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Barracuda-Email-Gateway-Add-on-Field-Extraction-not-Extracting/m-p/683496#M114092</link>
      <description>&lt;P&gt;Hey thanks for the reply!&lt;/P&gt;&lt;P&gt;Honestly, I forgot about this post or I would have updated it. It seems like the add-on is for a different version of the Barracuda Email Defense than we have. The Barracuda syslog documentation shows a log format that is different than what our cloud platform is sending, but does match what this add-on is looking for. I believe the add-on may be for a self-hosted or on-prem solution.&lt;/P&gt;&lt;P&gt;I was able to parse our logs by a field extraction spath on the extracted JSON. Unfortunately, nothing in the logs easily indicates email directionality, so that's a pain.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2024 20:54:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Barracuda-Email-Gateway-Add-on-Field-Extraction-not-Extracting/m-p/683496#M114092</guid>
      <dc:creator>BoxerguyT89</dc:creator>
      <dc:date>2024-04-06T20:54:04Z</dc:date>
    </item>
  </channel>
</rss>

