Getting Data In

splunk and clamav logfile monitoring

splunknewby2021
Observer

I'm trying to configure Splunk to analyze logs coming from ClamAV.

I have a shared folder where the logs are coming in.

On the machine where the shared folder is located, I set the universalforwarder to monitor that folder with this command:

/opt/splunkforwarder/bin/splunk add monitor /shared/avlogs/ -index clamav -sourcetype clamav

Now it's happening that when I try to search

index="clamav" _raw="*FOUND*"

I don't get results everytime, but depends on the content of the logfile, like if the parsing was not done correctly. What am I missing?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...