Any thoughts on why the new Splunk Add-on for Bro IDS isn't formatting the BRO fields in the files? Do I need to manually re-create them? None of these fields are coming in:
ts
uid
id.orig_h id.orig_p id.resp_h
id.resp_p
proto
service
duration orig_bytes
resp_bytes
conn_state
local_orig
missed_bytes
history
orig_pkts
orig_ip_bytesresp_pkts
resp_ip_bytes
tunnel_parents
What am I doing wrong!!!! Thanks in advance!
It is supposed to parse the fields, and it continues to do so in our automated tests and demo environments. I don't know what you're doing differently. You could file a ticket, since it's a supported app, or follow the troubleshooting tips at http://docs.splunk.com/Documentation/AddOns/released/Overview/Troubleshootadd-ons
Yes thanks rsennett, I'm only running the TA on a heavy forwarder & Indexer, in trouble-shooting I also removed the heavy as a possible issue, still the TA isn't extracting the fields....
Thanks
Where have you installed the add-on? The Add on uses python scripts...
Initially I stated that the UF could not run scripts but I was mistaken. I believe early versions did not but what was most likely the problem was that the UF user ID didn't have permission to execute etc... Sorry for the confusion.
That did it for me. I kept trying to use the app in conjunction with a Universal Forwarder, which would set the source type correctly but not generate the fields correctly. Switched to a heavy forwarder and everything's working great now, though. Thanks!
I have a fear that this issue is happening only to those running Splunk Light; if the Bro IDS add-on is not supported with universal forwarders, then by extension, it won't work with Splunk Light.
Thoughts?