All Apps and Add-ons

how to integrate splunk and snort in different machines?

zippyopsadmin
New Member

In my snort tool in centos7 and then splunk in another machine , so I plan to integrate the splunk and snort so i just install the splunk for snort app in splunk but i did not get the dashboard if any know means let me know

0 Karma

zippyopsadmin
New Member

i am also try with same machine in splunk and snort that way also i am not getting dashboard like data and then
i just manually data add in snort.log in splunk at that time also i am not getting the dashboard data

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Co-locating Splunk and Snort is not sufficient. You must tell Splunk where to find the Snort data and how to process it. Have you done that?
What steps did you take to manually add the Snort data? What sourcetype did you choose? What index did you choose? The index and sourcetype names must match those expected by the dashboard.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That app is very old so it may not be working properly under newer versions of Splunk.
How are you feeding Snort data into Splunk? It's not enough to just install the Snort app. Did you also enable the appropriate inputs as per the documentation?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...