Hi, I have a IDS system running snort on WINIDS (Win7). How do I get splunk to connect and collect info ?
I have no experience with WINIDS myself, but looking at the information pages it seems it comes preconfigured with Snort logging to a local MySQL database. In order to have Splunk read it, you will need to configure to log either to a file or via syslog (I found instructions on the latter here: http://www.winsnort.com/index.php?module=Pages&func=display&pageid=21). Reading events from a MySQL database is not supported, mostly because of the lack of a unified way to query databases from Splunk.