Archive

Native fields not visible (Real-Time Output App)

jonathan_cooper
Communicator

Using the output assistant, and configuring the base of my search (i.e. sourcetype="wineventlog:security"), I see results showing up in CEF format but the "Splunk Fields" section is always blank. I tried in both IE and FireFox just to ensure it wasn't a browser rendering issue. Any ideas or is it still possible to use fields that I know exist? The drag and drop portion is not working because of this.

I've been able to glean the following search terms to modify the CEF output:

.. | eval cef_override_map="host:dvchost"
.. | eval cef_static_map="cef_dvendor:Microsoft"

Are there any others? Do you happen to have a README on these? I'm fine bypassing the output assistant if I can get an understanding of how the searches work to convert the outputs to CEF. Thanks!

1 Solution

bkilroe
Engager

I managed to get it working by looking at the python scripts. You need to use cef_field_map rather than cef_override_map

index=_internal source="*web_access.log" | eval cef_field_map="host:dvchost,source:fname,spent:cn1,useragent:cs1,user:duser,status:cn2,clientip:dvc,method:cs2,bytes:cn3"

View solution in original post

bkilroe
Engager

I managed to get it working by looking at the python scripts. You need to use cef_field_map rather than cef_override_map

index=_internal source="*web_access.log" | eval cef_field_map="host:dvchost,source:fname,spent:cn1,useragent:cs1,user:duser,status:cn2,clientip:dvc,method:cs2,bytes:cn3"

View solution in original post

Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.