Dashboards & Visualizations

How to integrate OSSEC with Splunk.

azimzores
New Member

I am abit new to Splunk. I have setup the ossec server with: 6.7.8.9 10002

using the IP of the SPLUNK server. I have successfully installed the Ossec APP, it is not geting any data into Splunk when i look at the dashboard, what other configuration am i missing?

Tags (3)
0 Karma

southeringtonp
Motivator

As rayfoo suggested, a clearer explanation of what you mean by "limited data" would go a long way toward understanding your problem.

This is a fairly old question, so not sure if it's still an issue, but here are some things to try / questions to ask when troubleshooting:

  • Are you running the latest version of the Splunk for OSSEC App? There have been some significant changes from 1.0.x to 1.1.x of the app, and there will be several more in 1.2.x.

  • Does the issue appear with just dashboards, or do you have issues with the saved searches as well? What happens if you search on sourcetype=ossec* ?

  • Do the records coming into Splunk have the correct sourcetype? See the Data Inputs section of the README file for the recommended sourcetype values. If they are incorrect, you may need to adjust your Inputs configuration.

  • The dashboards currently look for specific OSSEC servers, so try running the search:
    | inputlookup lookup_ossec_servers and make sure your servers are listed. Also, make sure that the default wildcard entry for "All OSSEC Servers" is present. If not, there's a saved search that rebuilds the lookup table, so you might try running that.

    0 Karma

    jrodman
    Splunk Employee
    Splunk Employee

    Have you already read the installation text here?

    0 Karma

    rayfoo
    Path Finder

    Please explain more on what you mean by "limited data"?

    0 Karma

    azimzores
    New Member

    Yes, seems like limited data is following over.

    0 Karma
    Got questions? Get answers!

    Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

    Meet up IRL or virtually!

    Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

    Get Updates on the Splunk Community!

    Defend at Machine Speed: Your Guide to Security Sessions at .conf26

    Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

    Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

    If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

    Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

    The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...