<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Bro 2.6.4 forward to splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Bro-2-6-4-forward-to-splunk/m-p/471748#M81055</link>
    <description>&lt;P&gt;I am not the best with setup so i am looking for an all in one step by step for getting bro logs into splunk. I previously had the logs forwarded but the fields were not showing up. Here is my setup thus far:&lt;BR /&gt;
Bro 2.6.4 on Ubuntu server 18.04 LTS (fresh Install based on &lt;A href="https://wpcademy.com/how-to-install-bro-network-security-monitor-on-ubuntu-16-04-lts/"&gt;https://wpcademy.com/how-to-install-bro-network-security-monitor-on-ubuntu-16-04-lts/&lt;/A&gt; minus the geoIP stuff)&lt;BR /&gt;
Splunk Enterprise 8.0.1 (fresh install based on &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.1/Installation/InstallonLinux"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.1/Installation/InstallonLinux&lt;/A&gt;)&lt;BR /&gt;
    started and created admin&lt;BR /&gt;
    configured to start on boot&lt;BR /&gt;
I just see so many bits and pieces of what to do next to get Bro logs into Splunk i find myself doing the trial and error thing.&lt;BR /&gt;
Thank you for any help (i know this can't be that difficult)&lt;/P&gt;</description>
    <pubDate>Sat, 21 Dec 2019 13:16:54 GMT</pubDate>
    <dc:creator>tazzvon</dc:creator>
    <dc:date>2019-12-21T13:16:54Z</dc:date>
    <item>
      <title>Bro 2.6.4 forward to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Bro-2-6-4-forward-to-splunk/m-p/471748#M81055</link>
      <description>&lt;P&gt;I am not the best with setup so i am looking for an all in one step by step for getting bro logs into splunk. I previously had the logs forwarded but the fields were not showing up. Here is my setup thus far:&lt;BR /&gt;
Bro 2.6.4 on Ubuntu server 18.04 LTS (fresh Install based on &lt;A href="https://wpcademy.com/how-to-install-bro-network-security-monitor-on-ubuntu-16-04-lts/"&gt;https://wpcademy.com/how-to-install-bro-network-security-monitor-on-ubuntu-16-04-lts/&lt;/A&gt; minus the geoIP stuff)&lt;BR /&gt;
Splunk Enterprise 8.0.1 (fresh install based on &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.1/Installation/InstallonLinux"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.1/Installation/InstallonLinux&lt;/A&gt;)&lt;BR /&gt;
    started and created admin&lt;BR /&gt;
    configured to start on boot&lt;BR /&gt;
I just see so many bits and pieces of what to do next to get Bro logs into Splunk i find myself doing the trial and error thing.&lt;BR /&gt;
Thank you for any help (i know this can't be that difficult)&lt;/P&gt;</description>
      <pubDate>Sat, 21 Dec 2019 13:16:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Bro-2-6-4-forward-to-splunk/m-p/471748#M81055</guid>
      <dc:creator>tazzvon</dc:creator>
      <dc:date>2019-12-21T13:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Bro 2.6.4 forward to splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Bro-2-6-4-forward-to-splunk/m-p/471749#M81056</link>
      <description>&lt;P&gt;@tazzvon &lt;/P&gt;

&lt;P&gt;Have you tried &lt;STRONG&gt;Splunk Add-on for Zeek aka Bro&lt;/STRONG&gt;? &lt;/P&gt;

&lt;P&gt;The Splunk Add-on for Zeek aka Bro supports two log formats: TSV and JSON. JSON format is support for &lt;STRONG&gt;Zeek aka Bro&lt;/STRONG&gt; versions 2.3.x, 2.4.x, and 2.5.x. Not sure about 2.6.x but you can try if there are no change logs. &lt;/P&gt;

&lt;P&gt;Splunkbase link: &lt;A href="https://splunkbase.splunk.com/app/1617/"&gt;https://splunkbase.splunk.com/app/1617/&lt;/A&gt; ?&lt;BR /&gt;
Documentation: &lt;A href="https://docs.splunk.com/Documentation/AddOns/released/BroIDS/Description"&gt;https://docs.splunk.com/Documentation/AddOns/released/BroIDS/Description&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can find bro configuration in below link.&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/BroIDS/Configuration#Configure_Bro_log_monitoring"&gt;https://docs.splunk.com/Documentation/AddOns/released/BroIDS/Configuration#Configure_Bro_log_monitoring&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2019 11:00:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Bro-2-6-4-forward-to-splunk/m-p/471749#M81056</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2019-12-24T11:00:29Z</dc:date>
    </item>
  </channel>
</rss>

