All Apps and Add-ons

FireEye app and eMPS

hcpr
Path Finder

Hi.

I hope someone has had success with this. I've gotten the FireEye app up and working with the xml alerts from our WebMPS, so I added reporting from our email MPS.
The data shows up in Splunk, but the FireEye app does not see this data for some reason.
I haven't started digging much in the problem, but I suspect that there are some fields that differ between these two.

Has anyone else looked into this?

Thanks.

Tags (2)
0 Karma

PrinceOfEval
Path Finder

Howdy.

I've looked into this a little bit. The FireEye app on SplunkBase seems to be pretty outdated and not very good. If you look at the props.conf and transforms.conf that are included you'll see that the field extractions don't seem to address the email MPS alerts at all. For example, there's no extraction for the source email address.

If you have the logs in XML format, you can use "kv_mode = xml" in props.conf to automatically extract all the XML fields. The automatic extraction tends to yield very complicated field names. This is kind of messy, but you can make it a little better by creating field aliases to give simpler names to the fields you really care about.

0 Karma

hcpr
Path Finder

Thanks for the tip on kv_mode. I was starting to look in that direction myself.
It's going to be a bit time consuming I think, but I'll see what I can do.

I can always hope that the "official" app is updated 🙂

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...