Dashboards & Visualizations

Remote OSSEC servers not showing up in ossec dashboard server dropdown

claytonknorr
New Member

I have remote OSSEC servers successfully sending messages to splunk as well as a local OSSEC server. When I look at the events, all appears fine. However, when I go to the Splunk for OSSEC dashboard, if I select all servers I see the events from the remote server and the local one but I can't select the specific remote server. My only options are the local server or all servers. How do I let splunk know about the additional server(s) so they show up in the list?

Tags (1)
0 Karma

southeringtonp
Motivator

A few questions...

  • For your OSSEC events, what server name shows up in the ossec_server field?
  • How is Splunk getting data from OSSEC (is it reading alerts.log, or taking it in via syslog)?
    • Which sourcetype do your OSSEC events have (should be ossec or ossec_alerts)
    • Are OSSEC and Splunk on the same server?

The dropdown box is populated based on a lookup table, and the lookup table is generated based on the value of ossec_server in individual events. So you need to make sure that your events have the correct value in that field.

Also, if you make changes be sure to rebuild the lookup table: Searches & Reports -> Utility -> OSSEC - Rebuild OSSEC Server Lookup Table.

0 Karma

claytonknorr
New Member

I noticed that eventually after putting the name of my server (which was in the hosts file) into the ossec_serers.conf file, the server name would show up but had no events associated with it. I could only get the events to be tied to a server by putting in the IP address in ossec_servers.conf. Is there some way around this issue?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...