Getting Data In

windows_snare_syslog sourcetype but no field extractions?

Runals
Motivator

Perhaps I was over thinking this when I set a sourcetype to windows_snare_syslog - are there no field extractions build "out of the box" so to speak? We are running v5

Tags (1)
0 Karma
1 Solution

Ayn
Legend

Ayn
Legend

Runals
Motivator

Thanks Ayn. I had seen that but the word "expanded" in the description implied to me that there might be some additional out of the box field extractions for snare that I wasn't seeing for whatever reason. Guess not; will check it out.

0 Karma

Runals
Motivator

I did just look and am seeing that. The disappointing thing is the syslog-extractions in the transforms.conf is just for process and pid. Had hoped for more value from this sourcetype w/o me having to develop it =).

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Over here there is a field extraction windows_snare_syslog : REPORT-syslog that maps to the field transformation syslog-extractions.

Are you not seeing that, or is that not doing what you expected?

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...