All Apps and Add-ons

There is no OSSEC index in the Reporting and Management for OSSEC app. Will it take main?

ben_leung
Builder

Reporting and Management for OSSEC

There is no index.conf for making sure that it is search able.

0 Karma

southeringtonp
Motivator

In the current version, OSSEC events will go to Splunk's default main and summary indexes.

This could change at some point in the future -- having it be more configurable is on the wishlist.

In the meantime, you can configure it to use a dedicated ossec if you wish. It shouldn't require a huge effort -- you would need to create the index, making it default-searchable, and also update the inputs.conf entries to send events to it. If you also want to use a dedicated ossec_summary index, you'll need to update the populating saved searches as well as the search strings embedded in the OSSEC Summary Dashboard.

0 Karma

ben_leung
Builder

Actually I agree that not having an index.conf in the app is good. It leaves the option for the user to setup how they expect the index to retain/store the data. Most apps I have used came with an index.conf, which was the norm for me.

0 Karma

southeringtonp
Motivator

When the app was initially written, there were a lot of people using it with the free version of Splunk and not indexing other data. In that scenario, having a dedicated index was a little silly and more likely to be confusing than helpful. I've personally been frustrated in the past by apps that created indexes for what was low-volume data in our environment and potentially screwing up existing index design. But for people with larger Splunk deployments and multiple needs, using a separate index makes a lot of sense. So it really comes down to your use case.

0 Karma

ben_leung
Builder

so i guess we can just configure it, or let it go into main

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...