Installation

How to install Snort for Splunk

rweales
Explorer

I have Snort forwarding syslog to my Splunk server. I can see the Snort alerts show up in Splunk.

How do I get the "Splunk for Snort" app to show this data? I have installed the app and can pull it up, but it's empty...

According to install instructions:
"You will need to enable the appropriate inputs, either via inputs.conf, or through the Manager in the Splunk GUI."

I'm not sure how to go about doing this. I already have a port 514 UDP input(which is how Snort alerts are getting to Splunk.) I can't add another.

Thanks
Ron

Tags (1)
0 Karma

Ayn
Legend

You'd need to rewrite the sourcetype based on something that uniquely identifies the logs as Snort logs, like that they come from a certain host, contain something unique to Snort, etc. sourcetype rewriting is totally doable but I imagine can cause some confusion if you're new to Splunk. Here's an answer that can get you going: http://splunk-base.splunk.com/answers/34251/udp514-and-source-types

Also this: http://docs.splunk.com/Documentation/Splunk/5.0/Data/Advancedsourcetypeoverrides

rweales
Explorer

Forgive me for my newbness on this topic but I don't understand how to change the sourcetype.

It appears that I do that in the Splunk Data Preview app. How? Create a new Event Type?

0 Karma

Ayn
Legend

Then you need to resolve that. As the documentation for the app says, the sourcetype needs to be "snort_alert_fast" for the "fast" log format, and "snort_alert_full" for the full log format.

0 Karma

rweales
Explorer

The sourcetype is syslog.

0 Karma

Ayn
Legend

What sourcetype do your Snort events have?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...