All Apps and Add-ons

sourcetype broken

ShaunBaker
Path Finder

So with lots of trail and error, I've found that why both the Splunk for Snort and Snort for Splunk apps are not working because when I give the data input a sourcetype of "snort", splunk simply does not ingest the data coming in from barnyard2 via snort via pfSense. If I change sourcetype to "syslog", then I see events rolling into the index- if I search that index it is valid snort logs (albeit not field extracted because of being the wrong sourcetype).

What could be "braking" the sourcetype ingestion?

0 Karma
1 Solution

fugglefeet
Explorer

Hi ShaunBaker,

Is your question about Splunk for Snort or about Snort for Splunk? The Splunk for Snort app is developed by another author while I developed Snort for Splunk. Have you read the included README files of both apps to see how the apps are configured to work in the various environments?

fugglefeet

View solution in original post

0 Karma

fugglefeet
Explorer

Hi ShaunBaker,

Is your question about Splunk for Snort or about Snort for Splunk? The Splunk for Snort app is developed by another author while I developed Snort for Splunk. Have you read the included README files of both apps to see how the apps are configured to work in the various environments?

fugglefeet

0 Karma

ShaunBaker
Path Finder

It was in regards to either, as both are set to use that sourcetype. Strangely it started working, I suppose a reboot should have been done instead of a debug/refresh? Maybe it was my pfSense/Barnyard2 having some kind of lag.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...

From Data Landing to Insight

Search Across More of Your Data Ecosystem The data you need may live in Splunk, high-volume machine data, ...