All Apps and Add-ons

Can Splunk monitor two directories for Bro?

voorhees38
Engager

If so, does it require simply a second monitor line in the local/inputs.conf file for the app?

adonio
Ultra Champion

yes,

add another monitor stanza
read here:
http://docs.splunk.com/Documentation/AddOns/released/BroIDS/Configuration
and here:
http://docs.splunk.com/Documentation/AddOns/released/BroIDS/DataTypes

make sure the specify the sourcetype as bro

hope it helps

0 Karma
Get Updates on the Splunk Community!

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...