Getting Data In

TrendMicro deepdicovery app settings

bbiswabhusan
Explorer

Hello Team,

I am trying to setup the TrendMicro DeepDiscovery app to process the DDA/DDI events. I also have TrendMicro IWSVA hosts. After the app is installed in SH, I am redirected to the app setup page. Ihave replaced the default index in Deep Discovery Event Type i.e. ddi_index with the index that I had created with custom inputs. Similarly i have replaced the index name for Web Access Log Event Type as well with new index name. But the logs with sourcetype"squid"are still going to the default index log_index. Can someone suggest how we can troubleshoot it. Also, can someone suggest what should be the sourcetype for the DDA/DDI and IWSVA logs.

 

Any help/suggestion is helpful.

Thanks

Labels (3)
0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>