<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firegen for Snort splunk in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Firegen-for-Snort-splunk/m-p/451896#M8671</link>
    <description>&lt;P&gt;Yes, DB Connect does not have to be installed on the same server as the database - in fact it is very much recommended against.&lt;/P&gt;

&lt;P&gt;Best practice is to install a dedicated DBX heavy forwarder, which is separate from both the Splunk indexers and your DB servers.&lt;/P&gt;

&lt;P&gt;You will need to configure a connection for DBX to connect to the remote server, but this is just the same as any other multi tier application&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/DBX/3.1.4/DeployDBX/HowSplunkDBConnectworks"&gt;https://docs.splunk.com/Documentation/DBX/3.1.4/DeployDBX/HowSplunkDBConnectworks&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Mar 2019 11:49:46 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2019-03-21T11:49:46Z</dc:date>
    <item>
      <title>Firegen for Snort splunk</title>
      <link>https://community.splunk.com/t5/Installation/Firegen-for-Snort-splunk/m-p/451895#M8670</link>
      <description>&lt;P&gt;anybody knows how to install &amp;amp; configure Firegen for Snort splunk?&lt;BR /&gt;
in this case, I have 2 different servers, where Snort is separate from Splunk Server.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;scenario&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;Snort Dedicated server: 192.168.1.89&lt;BR /&gt;
Splunk Server: 192.168.1.113&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;in readme.txt file, developers said.. he has a case where Splunk &amp;amp; Snort is on the same server, it's because he used Splunk DB Connect App to get log data from snort DB (MySQL).&lt;/P&gt;

&lt;P&gt;So, what I want to ask, can I use a method that is almost the same but different server?&lt;/P&gt;

&lt;P&gt;Please.. help me, every help would be appreciated&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;&lt;IMG src="https://splunkbase.splunk.com/app/4118/" alt="Splunk Apps: Firegen for Snort" /&gt;&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/4118/"&gt;https://splunkbase.splunk.com/app/4118/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6746iC5E813FCD1270F05/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 11:40:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Firegen-for-Snort-splunk/m-p/451895#M8670</guid>
      <dc:creator>gibranduatiga</dc:creator>
      <dc:date>2019-03-21T11:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: Firegen for Snort splunk</title>
      <link>https://community.splunk.com/t5/Installation/Firegen-for-Snort-splunk/m-p/451896#M8671</link>
      <description>&lt;P&gt;Yes, DB Connect does not have to be installed on the same server as the database - in fact it is very much recommended against.&lt;/P&gt;

&lt;P&gt;Best practice is to install a dedicated DBX heavy forwarder, which is separate from both the Splunk indexers and your DB servers.&lt;/P&gt;

&lt;P&gt;You will need to configure a connection for DBX to connect to the remote server, but this is just the same as any other multi tier application&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/DBX/3.1.4/DeployDBX/HowSplunkDBConnectworks"&gt;https://docs.splunk.com/Documentation/DBX/3.1.4/DeployDBX/HowSplunkDBConnectworks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 11:49:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Firegen-for-Snort-splunk/m-p/451896#M8671</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-21T11:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: Firegen for Snort splunk</title>
      <link>https://community.splunk.com/t5/Installation/Firegen-for-Snort-splunk/m-p/451897#M8672</link>
      <description>&lt;P&gt;so.. you mean, I need 3 servers?&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Splunk Server&lt;/LI&gt;
&lt;LI&gt;MySQL Server&lt;/LI&gt;
&lt;LI&gt;DBX Heavy Forwarder&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;bye the way, to be honest.. poor me, I don't know how to start.. i am stucked. can you teach me step by step?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 12:22:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Firegen-for-Snort-splunk/m-p/451897#M8672</guid>
      <dc:creator>gibranduatiga</dc:creator>
      <dc:date>2019-03-21T12:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: Firegen for Snort splunk</title>
      <link>https://community.splunk.com/t5/Installation/Firegen-for-Snort-splunk/m-p/451898#M8673</link>
      <description>&lt;P&gt;I assume you already have a MySQL server - perhaps installed on your Snort Server?&lt;/P&gt;

&lt;P&gt;'Ideally' you would install DBX on its own dedicated  heavy forwarder.&lt;BR /&gt;
This Forwarder sends its data to the Splunk Indexer.&lt;/P&gt;

&lt;P&gt;So yes, that is 3 systems in total, but i assume that the Snort server and Splunk server already exist?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 12:29:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Firegen-for-Snort-splunk/m-p/451898#M8673</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-21T12:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: Firegen for Snort splunk</title>
      <link>https://community.splunk.com/t5/Installation/Firegen-for-Snort-splunk/m-p/451899#M8674</link>
      <description>&lt;P&gt;Yes, I did it before..&lt;BR /&gt;
installing MySQL server in my Snort Server is done, and Splunk server is already exist..&lt;BR /&gt;
so.. now? what i should i do? creating the dedicated heavy forwarder server to install DBX on it? and then.. ?&lt;/P&gt;

&lt;P&gt;teach me my master..&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2019 12:35:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Firegen-for-Snort-splunk/m-p/451899#M8674</guid>
      <dc:creator>gibranduatiga</dc:creator>
      <dc:date>2019-03-21T12:35:51Z</dc:date>
    </item>
  </channel>
</rss>

