All Apps and Add-ons

Why isn't the data parsing while using Barracuda WAF/ADC Add-on for Splunk?

johnward4
Communicator

I'm sending Barracuda logs over UDP 514 and configuring my inputs to listen for, using the Barracuda WAF/ADC Add-on for Splunk :

[udp://514]
index = barracuda
source = barracuda:log
sourcetype = barracuda:log
disabled = 0

I'm only seeing the data coming into with a single eventtype = err0r and none of the fields are processed by the add-on props & transforms. I'm also looking to find a Barracuda app to display dashboard visualization with the data but none of the apps found in Splunkbase seem to work and/or outdated. Help appreciated, thanks, everyone.

0 Karma
1 Solution

ekost
Splunk Employee
Splunk Employee

The Add-on leverages index-time transformations. If the data is coming in, is going into the correct index, but is not being source typed properly, then most likely the Add-on has not beed installed on the appropriate node. At a minimum, it'll need to be on the indexers. But if you're doing the collection (your UDP input) on a heavy forwarder, the Add-on would need to be installed there.
If that all looks good, you should compare the data you've collected in your index to the samples provided in the Add-on in /Splunk_TA_barracuda_waf_adc/samples/. They'll need to match, as there are regular expressions controlling the source type assignments.

View solution in original post

0 Karma

ekost
Splunk Employee
Splunk Employee

The Add-on leverages index-time transformations. If the data is coming in, is going into the correct index, but is not being source typed properly, then most likely the Add-on has not beed installed on the appropriate node. At a minimum, it'll need to be on the indexers. But if you're doing the collection (your UDP input) on a heavy forwarder, the Add-on would need to be installed there.
If that all looks good, you should compare the data you've collected in your index to the samples provided in the Add-on in /Splunk_TA_barracuda_waf_adc/samples/. They'll need to match, as there are regular expressions controlling the source type assignments.

0 Karma
Get Updates on the Splunk Community!

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...

New Customer Testimonials

Enterprises of all sizes and across different industries are accelerating cloud adoption by migrating ...