All Apps and Add-ons

FireEye Add-on for Splunk Enterprise: Do I need to create a local/inputs.conf file on my index?

mikelauth
Explorer

Do I need to create a local/inputs.conf file on my index under this TA? If so what should it contain?

0 Karma

gerald_contrera
Path Finder

We have fireeye sending to syslog and syslog creating a folder and log file. Splunk then monitoring the folder. How can i configure the Fireeye add-on to monitor the folder or look at the data coming in via "Monitor Folder"?

0 Karma

mvquyet195
New Member

what information splunk can read from fireeye's logs?

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!