Dear Community,
I integrate the FireEye NX with Splunk, but logs are not parsing as expected. I was searching for relevant add-ons and application for FireEye. I found below add-on and app,
- https://splunkbase.splunk.com/app/1904 (fireeye add on)
- https://splunkbase.splunk.com/app/1845 (fireeye App).
While i was going through the documentation of these add-on and app, i found it only support Splunk Enterprise platform not Cloud.
Is there any other application or add-on of same functionality on Splunk Cloud?
As far as I remember, the addon isn't that great and has some problems with itself, especially with CEF events. Probably most reliable way of getting the data would be to send the jsons to HEC endpoint. Then you could extract CIM mappings from the app and wrap them into your own app.