Getting Data In

Cisco Umbrella Add-On for Splunk Version6 support

jonxilinx
Path Finder

Hi , does anyone have any experience with Parsing Version 6 schema of Umbrella logs

the release notes from the addon https://splunkbase.splunk.com/app/3926/ talks only of version5

1.0.5: Adds support for logging format version 5 + Firewall Logs

 

the change in Umbrella seems for my environment to be only from Version4 -> version6 and

"Schema upgrades are one way; you will not be able to revert this upgrade."

Its scary you cant revert

 

Anyone moved to version6 and did they make changes in the local/{props,transforms} ?

 

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...