Yes. In order to index OPSEC data you will need to have an LEA server and then configure Splunk to fetch the data from there. Instructions and binaries for enabling this can be found on in the Community Wiki. Note this solution is only supported on Linux and Solaris
answered 03 Feb '10, 21:04
Note: If you are installing it on 64-bit Debian linux you will also need the ia32 libs (run 'apt-get install ia32-libs') in addition to the other instructions.
answered 27 Jul '10, 17:36