<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configuring Splunk with a Snare/ Windows Security Log Sourcetype in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-Splunk-with-a-Snare-Windows-Security-Log-Sourcetype/m-p/50786#M9723</link>
    <description>&lt;P&gt;Ok, so for reasons beyond this discussion we are unable to use the universal forwarder.  So, we have decided to bring in our data using Snare.  Has anyone had any experience with creating a sourcetype for snare forwarded messages?&lt;/P&gt;</description>
    <pubDate>Fri, 30 Nov 2012 20:04:16 GMT</pubDate>
    <dc:creator>rmcdougal</dc:creator>
    <dc:date>2012-11-30T20:04:16Z</dc:date>
    <item>
      <title>Configuring Splunk with a Snare/ Windows Security Log Sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-Splunk-with-a-Snare-Windows-Security-Log-Sourcetype/m-p/50786#M9723</link>
      <description>&lt;P&gt;Ok, so for reasons beyond this discussion we are unable to use the universal forwarder.  So, we have decided to bring in our data using Snare.  Has anyone had any experience with creating a sourcetype for snare forwarded messages?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2012 20:04:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configuring-Splunk-with-a-Snare-Windows-Security-Log-Sourcetype/m-p/50786#M9723</guid>
      <dc:creator>rmcdougal</dc:creator>
      <dc:date>2012-11-30T20:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Splunk with a Snare/ Windows Security Log Sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-Splunk-with-a-Snare-Windows-Security-Log-Sourcetype/m-p/50787#M9724</link>
      <description>&lt;P&gt;There is pretrained sourcetype for this already. Last one in the table.  Just make sure to set your sourcetype manually to 'windows_snare_syslog'.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/Listofpretrainedsourcetypes" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Data/Listofpretrainedsourcetypes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:53:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configuring-Splunk-with-a-Snare-Windows-Security-Log-Sourcetype/m-p/50787#M9724</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2020-09-28T12:53:44Z</dc:date>
    </item>
  </channel>
</rss>

