All Apps and Add-ons

Splunk Add-on for Bromium: What is the input file?

brian_meyer
Explorer

Trying to figure this app out. In the directions, all it references is "the malware event logs file generated by the Bromium server", but doesn't give any more information to go on. The only log file that is on the Bromium server that contains the information I am looking for is the "default.log" log file, however, the Splunk_TA_Bromium add-on does not parse that correctly at all.

I've also tried importing the syslog data after forwarding it to a syslog server, but that doesn't seem to work either. The props.conf file in the app has KV_MODE = xml so I'm trying to look for an xml file, but not finding anything - definitely suggests that syslog is incorrect as well.

Can someone please try to point me in the right direction?

0 Karma
1 Solution

hunters_splunk
Splunk Employee
Splunk Employee

Hi brian,

The add-on monitors Bromium event logs, but the files may not end in .log extension. Please try to locate files with Xevts in the filenames. I think the location of the files should be configurable in Bromium, so you can also consult Bromium documentation for details.

Thanks!
Hunter Shen

View solution in original post

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi brian,

The add-on monitors Bromium event logs, but the files may not end in .log extension. Please try to locate files with Xevts in the filenames. I think the location of the files should be configurable in Bromium, so you can also consult Bromium documentation for details.

Thanks!
Hunter Shen

0 Karma

brian_meyer
Explorer

Awesome! Thanks for the help!

Don't suppose there is any Splunk app that helps parse out the Bromium syslog data then? That's contains the information I'm really interested in (file uploads, trusted file events, etc).

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...