Splunk Enterprise

Ironstream Data Monitor Json data Ingestion

Maxime
Loves-to-Learn

Hello,

I installed on Splunk IronStream Data Monitor to receive Json data created by an IBM i server and transmitted by python code. I can also send the data in syslog format.

I searched but I didn’t find documentation on how to set it on Splunk to receive the data.

I would also like to know if there are specific column names for the SIEM to understand the data received.

Example in my json file the Remote_IP column is the area that retrieves the attacker’s ip address.

thanks for reading.

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...