All Apps and Add-ons

Why isn't the new Splunk Add-on for Bro IDS 3.1.4 parsing Bro fields from the files?

cdupuis123
Path Finder

Any thoughts on why the new Splunk Add-on for Bro IDS isn't formatting the BRO fields in the files? Do I need to manually re-create them? None of these fields are coming in:

ts
uid
id.orig_h id.orig_p id.resp_h

id.resp_p

proto

service
duration orig_bytes

resp_bytes

conn_state

local_orig

missed_bytes

history
orig_pkts

orig_ip_bytesresp_pkts

resp_ip_bytes

tunnel_parents

What am I doing wrong!!!! Thanks in advance!

jcoates_splunk
Splunk Employee
Splunk Employee

It is supposed to parse the fields, and it continues to do so in our automated tests and demo environments. I don't know what you're doing differently. You could file a ticket, since it's a supported app, or follow the troubleshooting tips at http://docs.splunk.com/Documentation/AddOns/released/Overview/Troubleshootadd-ons

0 Karma

cdupuis123
Path Finder

Yes thanks rsennett, I'm only running the TA on a heavy forwarder & Indexer, in trouble-shooting I also removed the heavy as a possible issue, still the TA isn't extracting the fields....

stillstymied

Thanks

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

Where have you installed the add-on? The Add on uses python scripts...
Initially I stated that the UF could not run scripts but I was mistaken. I believe early versions did not but what was most likely the problem was that the UF user ID didn't have permission to execute etc... Sorry for the confusion.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!

bearda
Engager

That did it for me. I kept trying to use the app in conjunction with a Universal Forwarder, which would set the source type correctly but not generate the fields correctly. Switched to a heavy forwarder and everything's working great now, though. Thanks!

terencegoggin
Explorer

I have a fear that this issue is happening only to those running Splunk Light; if the Bro IDS add-on is not supported with universal forwarders, then by extension, it won't work with Splunk Light.

Thoughts?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...