All Apps and Add-ons

Why isn't the data parsing while using Barracuda WAF/ADC Add-on for Splunk?

johnward4
Communicator

I'm sending Barracuda logs over UDP 514 and configuring my inputs to listen for, using the Barracuda WAF/ADC Add-on for Splunk :

[udp://514]
index = barracuda
source = barracuda:log
sourcetype = barracuda:log
disabled = 0

I'm only seeing the data coming into with a single eventtype = err0r and none of the fields are processed by the add-on props & transforms. I'm also looking to find a Barracuda app to display dashboard visualization with the data but none of the apps found in Splunkbase seem to work and/or outdated. Help appreciated, thanks, everyone.

0 Karma
1 Solution

ekost
Splunk Employee
Splunk Employee

The Add-on leverages index-time transformations. If the data is coming in, is going into the correct index, but is not being source typed properly, then most likely the Add-on has not beed installed on the appropriate node. At a minimum, it'll need to be on the indexers. But if you're doing the collection (your UDP input) on a heavy forwarder, the Add-on would need to be installed there.
If that all looks good, you should compare the data you've collected in your index to the samples provided in the Add-on in /Splunk_TA_barracuda_waf_adc/samples/. They'll need to match, as there are regular expressions controlling the source type assignments.

View solution in original post

0 Karma

ekost
Splunk Employee
Splunk Employee

The Add-on leverages index-time transformations. If the data is coming in, is going into the correct index, but is not being source typed properly, then most likely the Add-on has not beed installed on the appropriate node. At a minimum, it'll need to be on the indexers. But if you're doing the collection (your UDP input) on a heavy forwarder, the Add-on would need to be installed there.
If that all looks good, you should compare the data you've collected in your index to the samples provided in the Add-on in /Splunk_TA_barracuda_waf_adc/samples/. They'll need to match, as there are regular expressions controlling the source type assignments.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...