Getting Data In

Cisco Umbrella Add-On for Splunk Version6 support

jonxilinx
Path Finder

Hi , does anyone have any experience with Parsing Version 6 schema of Umbrella logs

the release notes from the addon https://splunkbase.splunk.com/app/3926/ talks only of version5

1.0.5: Adds support for logging format version 5 + Firewall Logs

 

the change in Umbrella seems for my environment to be only from Version4 -> version6 and

"Schema upgrades are one way; you will not be able to revert this upgrade."

Its scary you cant revert

 

Anyone moved to version6 and did they make changes in the local/{props,transforms} ?

 

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...