Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Splunk Add-on for Bromium: What is the input file?

$
0
0
Trying to figure this app out. In the directions, all it references is "the malware event logs file generated by the Bromium server", but doesn't give any more information to go on. The only log file that is on the Bromium server that contains the information I am looking for is the "default.log" log file, however, the Splunk_TA_Bromium add-on does not parse that correctly at all. I've also tried importing the syslog data after forwarding it to a syslog server, but that doesn't seem to work either. The props.conf file in the app has `KV_MODE = xml` so I'm trying to look for an xml file, but not finding anything - definitely suggests that syslog is incorrect as well. Can someone please try to point me in the right direction?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>