All Apps and Add-ons

Sending Cisco Umbrella data to syslog server

mpuchalski
Loves-to-Learn

Anyone know how to configure the Cisco Umbrella Add-on to also send the Umbrella logs to a syslog server? 

I've tried the info here (https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd#Sysl...) but I seem to get all data coming into my splunk system, not just the Umbrella logs.

I'm wondering if there's a way to make it work for only the Umbrella data.

Thanks!

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...