Getting Data In

Indexing Ubisecure Ubilogin logs?

isoutamo
SplunkTrust
SplunkTrust

Hi

Have anyone indexed Ubisecure's Ubilogin audit or diag files? Basically those are CSV files, BUT depending of event there are different amount of columns even same type of even based on e.g. used authentication method.

time, src ip, action, user info, f1, f2, f3, f4
t1, src-1, authentication method list, _xyz, "CN=aa,OU=b....", "user agent"
t2, src-1, authentication method list, _xyz, password.xx, "CN=aa,OU=b....", "user agent"
t3, src-1, login, _xyz, yyy, password.xx, "CN=bb, OU=cc...", foo,...,...,..

Even same action can contain different amount of fields based on "user info" field.

There are some other actions too.

If there is no better solution then I probably try this: https://community.splunk.com/t5/Getting-Data-In/Indexing-a-CSV-data-file-with-more-than-one-set-of-d...

r. Ismo 

Labels (4)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...