All Apps and Add-ons

SPLUNK for SNORT not working

thunbolt22
Engager

I am trying to get SPLUNK for SNORT up and running with no luck. I am new to SNORT,SPLUNK, and linux in gerneral. But here is what i have.
CentOS running SNORT and producing an ALERT and log file
Windows PC running SPLUNK

I setup the universal forwarder and all my SNORT alerts appear in SPLUNK as sourcetype snort_alert_full using the following command:
/opt/splunkforwarder/bin/splunk add monitor /etc/log/snort/ -index main -sourcetype snort_alert_full

When viewing in Splunk for snort i have no results. my understanding is that when the data is processed it should be renames from snort_alert_full to snort, i dont see this happeneing. And cannot search for src_ip as it is not being indexed properly.

Is there something i have to do to get Splunk for snort to process the data and index it properly?

0 Karma
1 Solution

thunbolt22
Engager

I ended up reinstalling Splunk for Snort and everything worked.

View solution in original post

0 Karma

thunbolt22
Engager

I ended up reinstalling Splunk for Snort and everything worked.

0 Karma

starcher
Influencer

Try changing snort to alert fast. Then same for the file monitor for the splunk forwarder

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...