Monitoring Splunk

Possible bugs/typos

thipsz
Explorer

Propably event format for field transformations "outbound_interface_for_checkpoint" is incorrect and it should be "outbound_interface::$1"

Also fields extraction "opsec : REPORT-rule_for_opsec" refers to transform rule that doesn't exist.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Not a question, contact the App Author to report bugs/typos.

http://apps.splunk.com/app/1454/ - Check Contact info in the Bottom Right.

alacercogitatus
SplunkTrust
SplunkTrust

No worries, please accept this answer if it addressed your need. Thanks!

0 Karma

thipsz
Explorer

My appologies.

0 Karma
Get Updates on the Splunk Community!

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

Unlock Instant Security Insights from Amazon S3 with Splunk Cloud — Try Federated ...

Availability: Must be on Splunk Cloud Platform version 10.1.2507.x to view the free trial banner. If you are ...