All Apps and Add-ons

Security Onion App for Splunk software: How to get data from a Security Onion stand alone server into a stand alone Splunk server?

dt2525
New Member

Greetings,

I have set up a stand alone Security Onion server and stand alone Splunk server. I have followed the instructions on setting up the Security Onion App on Splunk. I have set up Security Onion to send events via SYSLOG to the Splunk server. I see the data coming in, but the Security Onion app is not parsing and not seeing the data via the dashboards.

What am I missing in the setup?

Can I do this using separate servers, or do they both have to be installed on the same box?

Do I use the standard SYSLOG data source, or do I need to use something like SNORT or other for the context of the data source?

Thanks....

0 Karma

ozirus
Path Finder
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...