All Apps and Add-ons

Native fields not visible (Real-Time Output App)

jonathan_cooper
Communicator

Using the output assistant, and configuring the base of my search (i.e. sourcetype="wineventlog:security"), I see results showing up in CEF format but the "Splunk Fields" section is always blank. I tried in both IE and FireFox just to ensure it wasn't a browser rendering issue. Any ideas or is it still possible to use fields that I know exist? The drag and drop portion is not working because of this.

I've been able to glean the following search terms to modify the CEF output:

.. | eval cef_override_map="host:dvchost"
.. | eval cef_static_map="cef_dvendor:Microsoft"

Are there any others? Do you happen to have a README on these? I'm fine bypassing the output assistant if I can get an understanding of how the searches work to convert the outputs to CEF. Thanks!

1 Solution

bkilroe
Engager

I managed to get it working by looking at the python scripts. You need to use cef_field_map rather than cef_override_map

index=_internal source="*web_access.log" | eval cef_field_map="host:dvchost,source:fname,spent:cn1,useragent:cs1,user:duser,status:cn2,clientip:dvc,method:cs2,bytes:cn3"

View solution in original post

bkilroe
Engager

I managed to get it working by looking at the python scripts. You need to use cef_field_map rather than cef_override_map

index=_internal source="*web_access.log" | eval cef_field_map="host:dvchost,source:fname,spent:cn1,useragent:cs1,user:duser,status:cn2,clientip:dvc,method:cs2,bytes:cn3"

Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...