All Apps and Add-ons

Splunk Add-on for OSSEC: Why are there missing files from add-on and where to find them?

davidschatz
New Member

The Splunk_TA_ossec files are missing from the Splunk Add-on for OSSEC:

splunk-add-on-for-ossec_401.tgz

Splunk documentation claims that they should be there for OSSEC dashboards:

 http://docs.splunk.com/Documentation/AddOns/released/OSSEC/Lookups

Anyone know where to find them?

Thanks.

0 Karma

davidschatz
New Member

Hi Hunter,

Thanks for your quick answer, and correct clarification.

My confusion was a result of there being TWO ossec config files:

1) ossec-hids-2.8.3.tar.gz -> installs ossec itself
2) splunk_add-on-for-ossec_401 -> installs Splunk_TA_ossec, for ossec/Splunk integration.

I had just missed the second one.

David

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi David,

After you install the add-on, the lookup files can be found in the installation directory here;

$SPLUNK_HOME/etc/apps/Splunk_TA_ossec/lookups/

Hope it helps. Thanks!
Hunter

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...