All Apps and Add-ons

Which Sourcetype for NGIPS?

morethanyell
Builder

The SplunkWorks-built TA called Splunk Add-on for Cisco FireSIGHT said in the description that it is able to parse NGIPS logs. But upon inspection of the `props.conf`, it doesn't have sourcetype for NGIPS. Which should I use? I tried the `cisco:sourcefire` but it's not working.

0 Karma

morethanyell
Builder

Thanks. It did not parse the fields of the logs. I ended up writing our own props for it.

0 Karma

ragedsparrow
Contributor

I think it would be `[cisco:sourcefire:appliance:syslog]` 

Also, that TA is out of support.  Cisco has released a supported addon to replace it here: https://splunkbase.splunk.com/app/3662/

Get Updates on the Splunk Community!

New Case Study: How LSU’s Student-Powered SOCs and Splunk Are Shaping the Future of ...

Louisiana State University (LSU) is shaping the next generation of cybersecurity professionals through its ...

Splunk and Fraud

Join us on November 13 at 11 am PT / 2 pm ET!Join us for an insightful webinar where we delve into the ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...