All Apps and Add-ons

Which Sourcetype for NGIPS?

morethanyell
Builder

The SplunkWorks-built TA called Splunk Add-on for Cisco FireSIGHT said in the description that it is able to parse NGIPS logs. But upon inspection of the `props.conf`, it doesn't have sourcetype for NGIPS. Which should I use? I tried the `cisco:sourcefire` but it's not working.

0 Karma

morethanyell
Builder

Thanks. It did not parse the fields of the logs. I ended up writing our own props for it.

0 Karma

ragedsparrow
Contributor

I think it would be `[cisco:sourcefire:appliance:syslog]` 

Also, that TA is out of support.  Cisco has released a supported addon to replace it here: https://splunkbase.splunk.com/app/3662/

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...