Getting Data In

Cisco Umbrella Add-On for Splunk Version6 support

jonxilinx
Path Finder

Hi , does anyone have any experience with Parsing Version 6 schema of Umbrella logs

the release notes from the addon https://splunkbase.splunk.com/app/3926/ talks only of version5

1.0.5: Adds support for logging format version 5 + Firewall Logs

 

the change in Umbrella seems for my environment to be only from Version4 -> version6 and

"Schema upgrades are one way; you will not be able to revert this upgrade."

Its scary you cant revert

 

Anyone moved to version6 and did they make changes in the local/{props,transforms} ?

 

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...