Getting Data In

Cisco Umbrella Add-On for Splunk Version6 support

jonxilinx
Path Finder

Hi , does anyone have any experience with Parsing Version 6 schema of Umbrella logs

the release notes from the addon https://splunkbase.splunk.com/app/3926/ talks only of version5

1.0.5: Adds support for logging format version 5 + Firewall Logs

 

the change in Umbrella seems for my environment to be only from Version4 -> version6 and

"Schema upgrades are one way; you will not be able to revert this upgrade."

Its scary you cant revert

 

Anyone moved to version6 and did they make changes in the local/{props,transforms} ?

 

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...