Getting Data In

Bro log ingestion and indexing

DarkMSTie
New Member

Hey all super new to splunk administration - I'm having issues with the bro logs being indexed properly
I have 2 days of logs from a folder - but when I go and search the index - despite Indexes showing millions of events existing, I only see the bro tunnel logs, and they're for the wrong day
I'm not even looking to set up all the sourcetypes and extractions at this moment. I just want all of the logs ingested and searchable on the correct day/time. 

I've played with the Bro apps and switching the config around in the props.conf. 
I've deleted the fishbucket folder to start over and force the re-indexing

Overall I feel like there's another step I'm missing. 

inputs.conf
[monitor://C:\bro\netflow]
disabled = false
host = MyHost
index = bro
crcSalt = <SOURCE>



1) why are the tunnel logs being indexed for the wrong day? How do I fix?
2) where are the rest of the logs and how do I troubleshoot? 

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @DarkMSTie,

identify the correct sourcetype is the first (and most important) categorization that you can do to recognize your Data Flows,

so don't leave to Splunk the choice of the sourcetype, also because in this way it probably will use a standard (as e.g. csv) sourcetype that could be common also with other Data Flows and you're not sure to identify only these logs.

So identify the sourcetype (e.g. "bro") in inputs.conf, eventually cloning an existing one (e.g. csv), so you are sure to identify your logs.

In addition, if this Data Flow has some different configuration, you can use it without problems to other data Flows.

In other words, the most important field to identify a Data Flow isn't index but sourcetype, also because you associate to sourcetype al the fields extractions, etc...

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...