Getting Data In

windows_snare_syslog sourcetype but no field extractions?

Runals
Motivator

Perhaps I was over thinking this when I set a sourcetype to windows_snare_syslog - are there no field extractions build "out of the box" so to speak? We are running v5

Tags (1)
0 Karma
1 Solution

Ayn
Legend

Ayn
Legend

Runals
Motivator

Thanks Ayn. I had seen that but the word "expanded" in the description implied to me that there might be some additional out of the box field extractions for snare that I wasn't seeing for whatever reason. Guess not; will check it out.

0 Karma

Runals
Motivator

I did just look and am seeing that. The disappointing thing is the syslog-extractions in the transforms.conf is just for process and pid. Had hoped for more value from this sourcetype w/o me having to develop it =).

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Over here there is a field extraction windows_snare_syslog : REPORT-syslog that maps to the field transformation syslog-extractions.

Are you not seeing that, or is that not doing what you expected?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...