Getting Data In

How to send an IP and MAC address to a router filter file

jcrochon
Explorer

I’m moving from custom software that writes a snort alert to a file that would filter the device on a router.

I’m not sure where to start but I’m hoping that there is a command line like “sendalert /var/log/$mac-$ip-filter.log” that will be processed upstream to the router by a cron job.

I would also like that a right-click on a Splunk search output to extract the same data and write to the file.

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...