Hi
for getting mikrotik logs in splunk i use mikrotik app.
i have a problem with show mikrotik events in splunk Enterprise Security (ES), nothing show. i have around 10M logs in splunk but all of my notables in ES are empty!
what can i do ?
in the first picture: 192.168.110.1 is my mikrotik routerboard:
in the second picture: as you see i have too many DNS activity:
and i the third picture: in ES APP nothing show:
Look at the corresponding thread on the Mikrotik forum:
no one answer me?