Getting Data In

Indexing Ubisecure Ubilogin logs?

isoutamo
SplunkTrust
SplunkTrust

Hi

Have anyone indexed Ubisecure's Ubilogin audit or diag files? Basically those are CSV files, BUT depending of event there are different amount of columns even same type of even based on e.g. used authentication method.

time, src ip, action, user info, f1, f2, f3, f4
t1, src-1, authentication method list, _xyz, "CN=aa,OU=b....", "user agent"
t2, src-1, authentication method list, _xyz, password.xx, "CN=aa,OU=b....", "user agent"
t3, src-1, login, _xyz, yyy, password.xx, "CN=bb, OU=cc...", foo,...,...,..

Even same action can contain different amount of fields based on "user info" field.

There are some other actions too.

If there is no better solution then I probably try this: https://community.splunk.com/t5/Getting-Data-In/Indexing-a-CSV-data-file-with-more-than-one-set-of-d...

r. Ismo 

Labels (4)
0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...