All Apps and Add-ons

How to get FireEye Data into Splunk?

mister_evan
New Member

Greetings Community!

I am working on a solution to get FireEye HX data into Splunk. I have found the document located here:

https://www.fireeye.com/content/dam/fireeye-www/global/en/partners/pdfs/config-guide-fireeye-app-for...

But it was written for Splunk 6.x, and I am using Splunk 7.x. My first question is whether the document is still valid or not.

Second, the FireEye App for Splunk Enterprise v3 was last updated Jan 2017. Can anybody confirm that it (still) works with current versions of Splunk and FireEye?

Thanks in advance.

0 Karma

muralikoppula
Communicator

You can still use that Document for configuration purpose. It doesn't matter whether you're using Splunk 6.x OR 7.x

Yes the FireEye app is currently supporting Splunk 6.x as per Splunk base but still you can use this for Splunk 7.x. Try to use app FireEye recommended sourcetypes so that you'll see all the field extractions properly.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...