Splunk Enterprise Security

how to integrate with splunk and alienvault ?

zippyopsadmin
New Member

AlienVault Ossim App by A3SEC
i just install the app and follow the document but i didnt get the dashboard same as alien vault to splunk
what can i do?

0 Karma

adonio
Ultra Champion

seems like a legacy app, if you look at the notes, it says you need Sideview Utils for the app, which makes me guess it uses Advanced XML which was depreciated probably 2 or 3 years ago ...
if the data is fine, and you can see it and work with it, i suggest that you will build your own dashboards.
you can always look at the source code of the views / dashboards and see what searches are running underneath

good luck

0 Karma

zippyopsadmin
New Member

Yes thank you for your response ,I am not expecting this answer, ok I just copy the alien valut syslog file and upload my file in splunk server and overwrite the ossim_internal source type these are all done means i am getting the a3sec app dashboard

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...