Installation

How to install Snort for Splunk

rweales
Explorer

I have Snort forwarding syslog to my Splunk server. I can see the Snort alerts show up in Splunk.

How do I get the "Splunk for Snort" app to show this data? I have installed the app and can pull it up, but it's empty...

According to install instructions:
"You will need to enable the appropriate inputs, either via inputs.conf, or through the Manager in the Splunk GUI."

I'm not sure how to go about doing this. I already have a port 514 UDP input(which is how Snort alerts are getting to Splunk.) I can't add another.

Thanks
Ron

Tags (1)
0 Karma

Ayn
Legend

You'd need to rewrite the sourcetype based on something that uniquely identifies the logs as Snort logs, like that they come from a certain host, contain something unique to Snort, etc. sourcetype rewriting is totally doable but I imagine can cause some confusion if you're new to Splunk. Here's an answer that can get you going: http://splunk-base.splunk.com/answers/34251/udp514-and-source-types

Also this: http://docs.splunk.com/Documentation/Splunk/5.0/Data/Advancedsourcetypeoverrides

rweales
Explorer

Forgive me for my newbness on this topic but I don't understand how to change the sourcetype.

It appears that I do that in the Splunk Data Preview app. How? Create a new Event Type?

0 Karma

Ayn
Legend

Then you need to resolve that. As the documentation for the app says, the sourcetype needs to be "snort_alert_fast" for the "fast" log format, and "snort_alert_full" for the full log format.

0 Karma

rweales
Explorer

The sourcetype is syslog.

0 Karma

Ayn
Legend

What sourcetype do your Snort events have?

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...