Getting Data In

How to route in two directions with restrictions on one?

BDein
Explorer

Hi,

Here is a challenge that works partly as expected.
On a HF I need to split syslog data to two different instances, one internal in the company, and secondly to an external company (that does investigations on these).
The external company has provided a sysmon config file, which collect all they need, but which on the other hand provides too much internally.

The split of data sending two ways works great using props, transforms and outputs.

Now the challenge is to remove some of the events send to the internal tcp group.
props.conf

 

[source::XmlWinEventLog:Microsoft-Windows-Sysmon/Operational]
TRANSFORMS-routing = sysmon-routeToExt, sysmon-routeToInt

 

transforms.conf

 

[sysmon-routeToInt]
SOURCE_KEY = MetaData:Host
REGEX = (?i)(.*)
DEST_KEY=_TCP_ROUTING
FORMAT=TcpOut_Int

[sysmon-routeToExt]
SOURCE_KEY = MetaData:Host
REGEX = (?i)(.*)
DEST_KEY=_TCP_ROUTING
FORMAT=TcpOut_Ext

 

One of the basic questions is: Is there a way to use props (order vise) so it will be possible to send everything to one tcp group (external), and with the same events then filter (drop some events using REGEX), and send the remaining events to the second tcp group (internal) ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

have you look CLONE_SOURCETYPE https://docs.splunk.com/Documentation/Splunk/latest/Admin/Transformsconf ?
That could help you?

r. Ismo

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...