All Apps and Add-ons

Omnibus to Splunk

adriandefry
New Member

Hello, I need to know if there is any tool/app to connect Omnibus to Splunk

I read this article but it seems it is old back from 2007 : https://www-304.ibm.com/software/brandcatalog/ismlibrary/details?catalog.label=1TW10NC1Z

Any info/help will be great.. Thanks

Tags (1)
0 Karma

a212830
Champion

Doesn't Ominbus have a flatfile gateway? Why not use that, and read it into Splunk?

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Doesn't appear to be anything updated and it doesn't mention the integration method. I believe OMNIbus has java and C API's that you could use to send events to Splunk however. If you wanted to do it via Syslog it looks like you'd have to provide that code yourself. Or even easier, get it out of OMNIbus to file and then let Splunk eat it.

0 Karma

e82than
Communicator

You need to also look out for VLAN network issues. Sometimes Tivoli netcool is created on another segment, and splunk on another thus they can't talk to each other on syslog. I have bumped into this problem 2x and most of the time is a network configuration issue. and it was an agentless splunk forwarder setup.

0 Karma

adriandefry
New Member

Thanks I might go with the second option to direct syslog part to a file & let Splunk eat it 🙂

Thank you!

0 Karma

adriandefry
New Member

Basically what I want is to get all the Omnibus alerts to Splunk (Via Syslog if possible)

0 Karma

adriandefry
New Member

Database + Gateway

0 Karma

a212830
Champion

Connect how? Probe? Database? Gateway?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...