I have managed to get Bro logs into Splunk, but even with the App/TA the data is still clunked together and not very searchable. Ive seen a few props.conf files here and there but has anyone had success with any?
↧