All Apps and Add-ons

Aside from Squid logs, what other log formats does Attack Scanner support?

masato_wang
Explorer

Aside from Squid logs, what other log formats does Attack Scanner support?

1 Solution

TrendMicro_Splu
Explorer

Attack Scanner supports the Web and Proxy data model of Common Information Model (CIM) add-on. If you have created a technology add-on that supports the Web and Proxy data model, you can set this source type through the app’s Settings screen.
Alternatively, take advantage of Splunk’s field alias to create an alias for specific fields. Note, however, that Attack Scanner uses src (traffic source) and dest (traffic destination) by default. To enable support, create another alias for your own source and destination fields.

View solution in original post

TrendMicro_Splu
Explorer

Attack Scanner supports the Web and Proxy data model of Common Information Model (CIM) add-on. If you have created a technology add-on that supports the Web and Proxy data model, you can set this source type through the app’s Settings screen.
Alternatively, take advantage of Splunk’s field alias to create an alias for specific fields. Note, however, that Attack Scanner uses src (traffic source) and dest (traffic destination) by default. To enable support, create another alias for your own source and destination fields.

Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...