Hi All,
My scenario: I receive log files from a customer which I need to analyze and build reports from it. I was able to import the data into Spunk, but it can't seem to work with any app I tried. I couldn't find the option to set data source for apps, are they only working with "forwarded" data?
Thanks,
Szabolcs
for your apps Splunk App for Checkpoint, Cisco Networks
, following this link for the best configurations
http://docs.splunk.com/Documentation/OPSEC-LEA/2.1.1/Install/InstalltheSplunkTechnologyAdd-onforChec...
In data summary page (page show by gyslainlatsa), select Sources
and in the displayed list click on your source to see if you have events
Yes I have events there and I'm they are visible in the Searching & reporting app but not in other apps.
Splunk App for Checkpoint, Cisco Networks
Many apps require that the data needs to flow through a particular add-on into Splunk. For instance, the blurb for the CheckPoint app indicates that it requires the data to be "collected using the Splunk Add-on for Check Point OPSEC LEA" for it to work. There are many Cisco apps, so I'm not sure which one you're using, but it may have similar requirements.
Oh that could be an issue! Will install the add-on and see if it works.
Thanks
Hi,
Thanks for your answer. I already checked it and I can see it in the sources and search. But if I open for example the Cisco app, it shows no data but there are Cisco logs in these sources.
your work with what apps?