All Apps and Add-ons

Reporting and Management for OSSEC: OSSEC logs are indexed and can be searched, but why are all dashboards empty?

ozirus
Path Finder

I'm sending OSSEC logs via syslog. All OSSEC logs are indexed and can be found using search, but all OSSEC dashboards are empty. Why is that?

0 Karma
1 Solution

ozirus
Path Finder

In your ossec.conf, please make sure that your log format is default not splunk or any other thing.

...
default
...

View solution in original post

ozirus
Path Finder

In your ossec.conf, please make sure that your log format is default not splunk or any other thing.

...
default
...

southeringtonp
Motivator

This is correct. The "splunk" option in ossec.conf was added by someone else long after the Splunk management app for OSSEC was written, and it does not follow the same logic. Counterintuitive though it may seem, using the "splunk" output option in ossec.conf is not recommended.

The other common source of this problem is if sourcetype is not set correctly for the incoming OSSEC logs.

Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...

Reminder! Splunk Love Promo: $25 Visa Gift Card for Your Honest SOAR Review With ...

We recently launched our first Splunk Love Special, and it's gone phenomenally well, so we're doing it again, ...