All Apps and Add-ons

Splunk for Symantec field extraction issue

jwalzerpitt
Influencer

I noticed that some fields within the Splunk for Symantec sourcetype=symantec:ep:security:file is not being properly extracted. For example, the Applications_Name field has time values:

2017-11-14 21:28:57
2017-11-14 21:31:29

begin_Time has protocol values:

ICMP
TCP
UDP

as well as some other fields with values that aren't matching up. Anyone else having this issue?

Thx

0 Karma

nychawk
Communicator

I do not believe these are fields that come with this app; they do not exist on my deployment, nor was I able to find "Applications_Name" anywhere in my servers.

I suspect these fields may have been locally grown, I suggest looking up their attributes/owner under field settings.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...