All Apps and Add-ons

There is no OSSEC index in the Reporting and Management for OSSEC app. Will it take main?

ben_leung
Builder

Reporting and Management for OSSEC

There is no index.conf for making sure that it is search able.

0 Karma

southeringtonp
Motivator

In the current version, OSSEC events will go to Splunk's default main and summary indexes.

This could change at some point in the future -- having it be more configurable is on the wishlist.

In the meantime, you can configure it to use a dedicated ossec if you wish. It shouldn't require a huge effort -- you would need to create the index, making it default-searchable, and also update the inputs.conf entries to send events to it. If you also want to use a dedicated ossec_summary index, you'll need to update the populating saved searches as well as the search strings embedded in the OSSEC Summary Dashboard.

0 Karma

ben_leung
Builder

Actually I agree that not having an index.conf in the app is good. It leaves the option for the user to setup how they expect the index to retain/store the data. Most apps I have used came with an index.conf, which was the norm for me.

0 Karma

southeringtonp
Motivator

When the app was initially written, there were a lot of people using it with the free version of Splunk and not indexing other data. In that scenario, having a dedicated index was a little silly and more likely to be confusing than helpful. I've personally been frustrated in the past by apps that created indexes for what was low-volume data in our environment and potentially screwing up existing index design. But for people with larger Splunk deployments and multiple needs, using a separate index makes a lot of sense. So it really comes down to your use case.

0 Karma

ben_leung
Builder

so i guess we can just configure it, or let it go into main

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...