Getting Data In

Cisco Umbrella Log Files- How do I create the custom event types to get there source and destination IP addresses?

TheSteveBennett
Observer

I am able to sync my data from the Cisco managed S3 bucket to a local folder on my heavy forwarder.  The files are comma delimited with  double quotes. With a comma and empty double quotes to show the end of the line (maybe)?

Example: 

"date time stamp","user","internal ip address",""

So how do I create the custom event types to get the source and destination IP Addresses.

 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...