All Apps and Add-ons

[Splunk Add-on for Bro IDS] When will the current Known Issues be addressed?

mikaelbje
Motivator

There haven't been any updates to the Splunk Add-on for BRO IDS since March 31 2015 and the list of known issues is giving me a few challenges.

I'm specifically interested in seeing these fixed:

Publication date Defect number Description

03/30/14 ADDON-3517 Fix event types and tags, make compliant

10/27/14 ADDON-2207 Several properties configured to extract bytes fields, which is not the correct method to do conditional field aliasing.

10/27/14 ADDON-2206 bro_action_lookup is not functioning.

04/24/14 ADDON-1379 Bro logs contain a field named 'host' that conflict with the Splunk's host field.

All of the above Known Issues are from 2014.

When can we expect an update?

Mikael

0 Karma
1 Solution

ehaddad_splunk
Splunk Employee
Splunk Employee

Hi,

Thank you for following up. We are working on releasing an update for the Splunk Add-on for Bro which includes fixes to the ones you have highlighted and others.
ADDON-2206 will not be fixed because a single event cannot have both conn_state & status fields to do the lookup. Events of sourcetype "bro_conn" have "conn_state" field, and sourcetype "bro_http" & "bro_ssh" events have "status" field. As a result, the "action" field that is outputted by both lookups will not conflict.

Let us know if you have any questions.

View solution in original post

ehaddad_splunk
Splunk Employee
Splunk Employee

Hi,

Thank you for following up. We are working on releasing an update for the Splunk Add-on for Bro which includes fixes to the ones you have highlighted and others.
ADDON-2206 will not be fixed because a single event cannot have both conn_state & status fields to do the lookup. Events of sourcetype "bro_conn" have "conn_state" field, and sourcetype "bro_http" & "bro_ssh" events have "status" field. As a result, the "action" field that is outputted by both lookups will not conflict.

Let us know if you have any questions.

jcoates_splunk
Splunk Employee
Splunk Employee

Hi Mikael, version 3.2.0 is now out with corrections to all of these issues (as Elias notes, ADDON-2206 was closed invalid).

http://docs.splunk.com/Documentation/AddOns/latest/BroIDS/Releasenotes

0 Karma

mikaelbje
Motivator

Thanks. 3.2.0 is looking better!

0 Karma

mikaelbje
Motivator

An update after about two weeks of use:

  1. Enterprise Security shows data from several of the bro_* sourcetypes
  2. SSL Activity in Enterprise Security not showing anything, even though we have bro_ssl data coming in. Should the bro_ssl sourcetype provide enough data to populate the SSL Activity dashboard? What other means do we have to get SSL sessions? Stream?
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...