All Apps and Add-ons

Why isn't the new Splunk Add-on for Bro IDS 3.1.4 parsing Bro fields from the files?

cdupuis123
Path Finder

Any thoughts on why the new Splunk Add-on for Bro IDS isn't formatting the BRO fields in the files? Do I need to manually re-create them? None of these fields are coming in:

ts
uid
id.orig_h id.orig_p id.resp_h

id.resp_p

proto

service
duration orig_bytes

resp_bytes

conn_state

local_orig

missed_bytes

history
orig_pkts

orig_ip_bytesresp_pkts

resp_ip_bytes

tunnel_parents

What am I doing wrong!!!! Thanks in advance!

jcoates_splunk
Splunk Employee
Splunk Employee

It is supposed to parse the fields, and it continues to do so in our automated tests and demo environments. I don't know what you're doing differently. You could file a ticket, since it's a supported app, or follow the troubleshooting tips at http://docs.splunk.com/Documentation/AddOns/released/Overview/Troubleshootadd-ons

0 Karma

cdupuis123
Path Finder

Yes thanks rsennett, I'm only running the TA on a heavy forwarder & Indexer, in trouble-shooting I also removed the heavy as a possible issue, still the TA isn't extracting the fields....

stillstymied

Thanks

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

Where have you installed the add-on? The Add on uses python scripts...
Initially I stated that the UF could not run scripts but I was mistaken. I believe early versions did not but what was most likely the problem was that the UF user ID didn't have permission to execute etc... Sorry for the confusion.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!

bearda
Engager

That did it for me. I kept trying to use the app in conjunction with a Universal Forwarder, which would set the source type correctly but not generate the fields correctly. Switched to a heavy forwarder and everything's working great now, though. Thanks!

terencegoggin
Explorer

I have a fear that this issue is happening only to those running Splunk Light; if the Bro IDS add-on is not supported with universal forwarders, then by extension, it won't work with Splunk Light.

Thoughts?

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...