I have the modsecurity app installed and all the third party apps installed in /opt/splunk/etc/apps. Data is being sent to splunk with the correct source and sourcetype, but the app doesn't create any charts. Any specific steps to complete the install?
Hello,
I also have the same problem. I can see the alert in the Overview Dashboard only in the window Modsec alert trend but don't get any data for modsec denied by ip or host. Splunk collects the data on a reverse proxy. Can this be the issue? (I also tried the above solution but without success...). Thanks
I got it working. In the Manager --> Fields --> Field Aliases, there were two settings. I removed the entry with xforwardedfor completely and changed the remaining "srcip AS clientip2" to "srcip AS clientip". Works beautifully.