Getting Data In

Cisco Umbrella Add-On for Splunk Version6 support

jonxilinx
Path Finder

Hi , does anyone have any experience with Parsing Version 6 schema of Umbrella logs

the release notes from the addon https://splunkbase.splunk.com/app/3926/ talks only of version5

1.0.5: Adds support for logging format version 5 + Firewall Logs

 

the change in Umbrella seems for my environment to be only from Version4 -> version6 and

"Schema upgrades are one way; you will not be able to revert this upgrade."

Its scary you cant revert

 

Anyone moved to version6 and did they make changes in the local/{props,transforms} ?

 

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...