Splunk Enterprise

Ironstream Data Monitor Json data Ingestion

Maxime
Loves-to-Learn

Hello,

I installed on Splunk IronStream Data Monitor to receive Json data created by an IBM i server and transmitted by python code. I can also send the data in syslog format.

I searched but I didn’t find documentation on how to set it on Splunk to receive the data.

I would also like to know if there are specific column names for the SIEM to understand the data received.

Example in my json file the Remote_IP column is the area that retrieves the attacker’s ip address.

thanks for reading.

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...