All Apps and Add-ons

sourcetype broken

ShaunBaker
Path Finder

So with lots of trail and error, I've found that why both the Splunk for Snort and Snort for Splunk apps are not working because when I give the data input a sourcetype of "snort", splunk simply does not ingest the data coming in from barnyard2 via snort via pfSense. If I change sourcetype to "syslog", then I see events rolling into the index- if I search that index it is valid snort logs (albeit not field extracted because of being the wrong sourcetype).

What could be "braking" the sourcetype ingestion?

0 Karma
1 Solution

fugglefeet
Explorer

Hi ShaunBaker,

Is your question about Splunk for Snort or about Snort for Splunk? The Splunk for Snort app is developed by another author while I developed Snort for Splunk. Have you read the included README files of both apps to see how the apps are configured to work in the various environments?

fugglefeet

View solution in original post

0 Karma

fugglefeet
Explorer

Hi ShaunBaker,

Is your question about Splunk for Snort or about Snort for Splunk? The Splunk for Snort app is developed by another author while I developed Snort for Splunk. Have you read the included README files of both apps to see how the apps are configured to work in the various environments?

fugglefeet

0 Karma

ShaunBaker
Path Finder

It was in regards to either, as both are set to use that sourcetype. Strangely it started working, I suppose a reboot should have been done instead of a debug/refresh? Maybe it was my pfSense/Barnyard2 having some kind of lag.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...