Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Splunk Add-On for Cisco ESA: How to create props.conf and transforms.conf for Cisco ESA/IronPort AMP logs?

$
0
0
Has anyone created props.conf and transforms.conf for the Splunk Add-On for Cisco ESA/IronPort AMP logs? Each step creates a log entry and the ESA App only does the MID. Each of the other events need to be split to make a meaningful alert. Such As: To: From: Subject: Attachment: Verdict: queued for delivery: Dropped by AMP:

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>