Getting Data In

Splunk windows logs to Snare central

rajeshmetso
Engager

Hi 

 

Am trying to collect the windows logs from DCs and send them to both Splunk indexer and Third party System (Snare Central). I managed to send the logs using syslog configuration. But some how the logs are getting broken. I want my log format to be in "snare over syslog". Please suggest.

UF => HF => Snare Central

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...