All Apps and Add-ons

Using Snare and Splunk App for Windows

rmcdougal
Path Finder

We are planning on using Snare to collect our desktop event logs. The problem is I haven't found a good way to integrate the Snare log format into the Splunk App for Windows. Has anyone tackled this task in the past?

http://splunk-base.splunk.com/apps/22315/

0 Karma

peterbarzen
New Member

You can send from Snare in generic syslog format.

0 Karma

treinke
SplunkTrust
SplunkTrust

Why not just use the Splunk for Windows in a light forwarder mode? This would allow you to send all the logs/data to Splunk without have the web interface on the host. Is there concerns about using the Splunk agent?

There are no answer without questions
0 Karma

treinke
SplunkTrust
SplunkTrust

Got any examples of the logs it is sending to Splunk?

There are no answer without questions
0 Karma

rmcdougal
Path Finder

The problem is that we have already deployed the Snare agent to our environment.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!