All Apps and Add-ons

Why isn't the data parsing while using Barracuda WAF/ADC Add-on for Splunk?

johnward4
Communicator

I'm sending Barracuda logs over UDP 514 and configuring my inputs to listen for, using the Barracuda WAF/ADC Add-on for Splunk :

[udp://514]
index = barracuda
source = barracuda:log
sourcetype = barracuda:log
disabled = 0

I'm only seeing the data coming into with a single eventtype = err0r and none of the fields are processed by the add-on props & transforms. I'm also looking to find a Barracuda app to display dashboard visualization with the data but none of the apps found in Splunkbase seem to work and/or outdated. Help appreciated, thanks, everyone.

0 Karma
1 Solution

ekost
Splunk Employee
Splunk Employee

The Add-on leverages index-time transformations. If the data is coming in, is going into the correct index, but is not being source typed properly, then most likely the Add-on has not beed installed on the appropriate node. At a minimum, it'll need to be on the indexers. But if you're doing the collection (your UDP input) on a heavy forwarder, the Add-on would need to be installed there.
If that all looks good, you should compare the data you've collected in your index to the samples provided in the Add-on in /Splunk_TA_barracuda_waf_adc/samples/. They'll need to match, as there are regular expressions controlling the source type assignments.

View solution in original post

0 Karma

ekost
Splunk Employee
Splunk Employee

The Add-on leverages index-time transformations. If the data is coming in, is going into the correct index, but is not being source typed properly, then most likely the Add-on has not beed installed on the appropriate node. At a minimum, it'll need to be on the indexers. But if you're doing the collection (your UDP input) on a heavy forwarder, the Add-on would need to be installed there.
If that all looks good, you should compare the data you've collected in your index to the samples provided in the Add-on in /Splunk_TA_barracuda_waf_adc/samples/. They'll need to match, as there are regular expressions controlling the source type assignments.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...