Security

Mikrotik APP and ES

ashkanarjmand
New Member

Hi

for getting mikrotik logs in splunk i use mikrotik app.
i have a problem with show mikrotik events in splunk Enterprise Security (ES), nothing show. i have around 10M logs in splunk but all of my notables in ES are empty!
what can i do ?

 

in the first picture: 192.168.110.1 is my mikrotik routerboard: 

in the second picture: as you see i have too many DNS activity: 

and i the third picture:  in ES APP nothing show:

 

i this picture: 192.168.110.1 is my mikrotik routerboard:i this picture: 192.168.110.1 is my mikrotik routerboard:as you see i have too many DNS activity:as you see i have too many DNS activity:but i ES nothing show:but i ES nothing show:

Labels (1)
Tags (2)
0 Karma

zandhaas
Explorer

Look at the corresponding thread on the Mikrotik forum:

https://forum.mikrotik.com/viewtopic.php?t=179960 

0 Karma

ashkanarjmand
New Member

no one answer me?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...