Activity Feed
- Posted Re: Splunk for IronPort on All Apps and Add-ons. 01-11-2013 11:58 AM
- Posted Re: Splunk for IronPort on All Apps and Add-ons. 01-11-2013 11:04 AM
- Posted Re: IP to Name on Splunk Search. 01-11-2013 08:53 AM
- Posted Re: IP to Name on Splunk Search. 01-11-2013 08:43 AM
- Posted IP to Name on Splunk Search. 01-11-2013 08:19 AM
- Tagged IP to Name on Splunk Search. 01-11-2013 08:19 AM
- Tagged IP to Name on Splunk Search. 01-11-2013 08:19 AM
- Tagged IP to Name on Splunk Search. 01-11-2013 08:19 AM
- Posted Re: Change source type on All Apps and Add-ons. 01-10-2013 01:36 PM
- Posted Splunk for IronPort on All Apps and Add-ons. 01-10-2013 01:07 PM
- Tagged Splunk for IronPort on All Apps and Add-ons. 01-10-2013 01:07 PM
- Tagged Splunk for IronPort on All Apps and Add-ons. 01-10-2013 01:07 PM
- Posted RADIUS Authentication on Security. 01-10-2013 01:06 PM
- Tagged RADIUS Authentication on Security. 01-10-2013 01:06 PM
- Posted Re: Change source type on All Apps and Add-ons. 01-10-2013 01:05 PM
- Posted Re: Change source type on All Apps and Add-ons. 01-10-2013 12:42 PM
- Posted Re: Change source type on All Apps and Add-ons. 01-10-2013 11:21 AM
- Posted Re: Change source type on All Apps and Add-ons. 01-10-2013 10:54 AM
- Posted Re: RiverBed Application on All Apps and Add-ons. 01-10-2013 10:15 AM
- Posted Re: Change source type on All Apps and Add-ons. 01-10-2013 10:10 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 |
01-11-2013
11:58 AM
Thanks.
I downloaded the addon as a .rar file.
How do I install that onto Splunk ?
README file doesn't tells that.
... View more
01-11-2013
11:04 AM
Thanks for the link.
I read through it.
My question now is, how do I point the IronPort to send data to Splunk ?
Thanks
Ansh
... View more
01-11-2013
08:53 AM
My entire props.conf reads :
[source::udp:514]
TRANSFORMS-changesourcetype = riverbed_steelhead, sourcetype_cisco_asa
[access_combined]
Lookup-hostnames = hostnames ip AS IP OUTPUTNEW Name
... View more
01-11-2013
08:43 AM
I tried this command., I still get the same error.
I also get the error :
Possible Typo in the first stanza [access_combined] in props.conf file.
... View more
01-11-2013
08:19 AM
I cannot get the hostnames in place of IP's on the summary screen. I need to get it done through the .csv file option and not DNS.
.CSV file contents reads :
IP,Name
10.12.0.132,AUS-BROCADE-10G-2
10.12.100.9,AUS-VG1
10.12.100.8,AUS-VG2
Transforms.conf :
[hostnames]
filename = hostnames.csv
props.conf :
[access_combined]
Lookup-hostnames = Hostnames ip AS IP OUTPUT Name
Can you tell me if there is something that I need to change.
I have added the .csv file as a lookup table, pointed a lookup definition to it.
When I perform this search :
sourcetype="syslog" | lookup hostnames host AS IP OUTPUT Name
I get the following error :
Error in 'lookup' command: Could not find all of the specified lookup fields in the lookup table
The .csv file is in the system/lookups folder.
... View more
01-10-2013
01:07 PM
Hi,
How do I send logs in real time from my IronPort working with E-mail Security Module ?
Thanks
... View more
01-10-2013
01:06 PM
Hi All,
Can I add users to Splunk using Active Directory groups ?
Or do I have to add them manually one by one ?
Thanks
Anshuman Jain
... View more
- Tags:
- radius
01-10-2013
01:05 PM
Thanks for the reply.
I am getting the logs sent to the new source type.
I still get that error though.
Can I have the logs to go to just the new sourcetype and not to syslogs at all ?
Thanks
... View more
01-10-2013
12:42 PM
I am new to this.
First time I am setting up Splunk. I am no where close to being a REGEX Guru.
The error that I get is :
I get the Error :
Possible typo in stanza [riverbed_steelhead] in transforms.conf. Line 4
Thanks
... View more
01-10-2013
11:21 AM
One thing I dont understand is, when I restart Splunk, why do I get the typo error ?
Is the above change going to make the IP addresses stop using syslog sourcetype and use just the riverbed_steelhead sourcetype ?
... View more
01-10-2013
10:54 AM
I am figuring it out.
I thought the backslash before every dot on the IP address was the right way to do it.
I am getting typos for the first line though.
Should I specify a source key ?
All I need is a way to have 10.10.20.185 use the sourcetype as riverbed_steelhead instead of syslog.
... View more
01-10-2013
10:15 AM
I am not getting the data in the riverbed_steelhead source type.
I get very few messages. 20 out of 8000 messages till now.
transforms.conf reads :
[riverbed_steelhead]
REGEX = (10.12.0.20:10.0.0.33:10.10.20.185)
DEST_KEY = MetaData:Sourcetype
FORMAT = sourcetype::riverbed_steelhead
Props.conf reads :
[source::udp:514]
TRANSFORMS-riverbed_src = riverbed_steelhead
... View more
01-10-2013
10:10 AM
there is a backslash before each ".", which for some reason is not showing up when I type it here.
... View more
01-10-2013
10:09 AM
I also tried : [10.12.0.20|10.0.0.33) and that did not work either.
I dont understand the typo in the first line.
... View more
01-10-2013
09:47 AM
** I am trying get the three IP addresses to use a new sourcetye when they send in data.
Props.conf reads :
[source::udp:514]
TRANSFORMS-riverbed_src = riverbed_steelhead
TRANSFORMS-changesourcetype = sourcetype_cisco_asa
transforms.conf reads :
[riverbed_steelhead]
REGEX = (10.12.0.20:10.0.0.33:10.10.20.185)
DEST_KEY = MetaData:Sourcetype
FORMAT = sourcetype::riverbed_steelhead
[sourcetype_cisco_asa]
REGEX = (10.12.254.1:10.10.20.254:10.1.250.254)
DEST_KEY = MetaData:Sourcetype
FORMAT = sourcetype::cisco_asa
I get the Error :
Possible typo in stanza [riverbed_steelhead] in transforms.conf. Line 4
Possible typo in stanza [sourcetype_cisco_asa] in transforms.conf. Line 10
Can someone help me find my problem please.
FYI : I also tried the format :
REGEX = (10.12.0.20|10.0.0.33|10.10.20.185)**
... View more
01-10-2013
09:46 AM
I have a similar problem. I am trying get the three IP addresses to use a new sourcetye when they send in data.
Props.conf reads :
[source::udp:514]
TRANSFORMS-riverbed_src = riverbed_steelhead
TRANSFORMS-changesourcetype = sourcetype_cisco_asa
transforms.conf reads :
[riverbed_steelhead]
REGEX = (10.12.0.20:10.0.0.33:10.10.20.185)
DEST_KEY = MetaData:Sourcetype
FORMAT = sourcetype::riverbed_steelhead
[sourcetype_cisco_asa]
REGEX = (10.12.254.1:10.10.20.254:10.1.250.254)
DEST_KEY = MetaData:Sourcetype
FORMAT = sourcetype::cisco_asa
I get the Error :
Possible typo in stanza [riverbed_steelhead] in transforms.conf. Line 4
Possible typo in stanza [sourcetype_cisco_asa] in transforms.conf. Line 10
Can someone help me find my problem please.
FYI : I also tried the format :
REGEX = (10.\12.0.20|10.0.0.33|10.10.20.185)
... View more
01-08-2013
10:22 AM
I added the Transforms commands to the props.conf file in Local Directory.
I also tried to change Riverbed_src = riverbed_steelhead.
I dont see that index being populated though.
... View more
01-08-2013
09:10 AM
The Devices are directly sending Syslogs to Splunk with UDP.
I can see the data in the Syslog Sourcetype, but when I go to the RiverBed app, I dont see any data.
I need to know how to get that data into the App.
Can I point to the devices ?
Thanks
... View more
01-08-2013
09:10 AM
The Devices are directly sending Syslogs to Splunk with UDP.
I can see the data in the Syslog Sourcetype, but when I go to the RiverBed app, I dont see any data.
I need to know how to get that data into the App.
Can I point to the devices ?
Thanks
... View more
01-08-2013
08:40 AM
I have three RiverNeds sending data into Splunk.
I downloaded and installed the RiverBed app and the RiverBed add on, but cant get the app to fetch data.
Can someone explain in detail how to achieve that.
Thanks
... View more
12-24-2012
08:05 PM
Thanks for the answer, but I still cannot find the fields.
Is there a syntax that I need to put in ?
Can you give me an example of it ?
Thanks
... View more
12-24-2012
11:51 AM
I have three Firewalls splunking, and I cannot see a src_ip or the URL fields in the search base.
Is there a way to get them.
I just started with Splunk so may be Don't have a lot of things required setup right now.
Any help or tips on starting Splunking that may be helpful in the future would be great.
Thanks all
Ansh
... View more
- Tags:
- s