Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Splunk addon for Bro IDS not automatically extracting fields

$
0
0
Hi, I have the a linux box running Bro 2.4 and the Splunk Universal forwarder (6.4.0) configured to monitor my bro logs and forward to an indexer running Splunk 6.4.0 with the Bro Addon installed. Splunk is setting the sorucetype correctly (bro_dhcp, bro_files ect..) however the automatic feature extraction is not working. Is there anything I am missing?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>