Refine your search:

Is Splunk 4.x able to eat messages in OPSEC formatted style? Are we able to read it in a human readable form via Splunk Search?

asked 02 Feb '10, 14:59

Simon's gravatar image

Simon
3773217
accept rate: 14%

edited 27 Jul '10, 22:49

Lionel's gravatar image

Lionel ♦♦
8341313


3 Answers:

Yes. In order to index OPSEC data you will need to have an LEA server and then configure Splunk to fetch the data from there. Instructions and binaries for enabling this can be found on in the Community Wiki. Note this solution is only supported on Linux and Solaris

link

answered 03 Feb '10, 21:04

matt's gravatar image

matt ♦♦
3.5k121140
accept rate: 81%

Simon -

Have a look at the discussion page on the community wiki as well, there are some potentially helpful caveats there.

link

answered 22 Mar '10, 11:17

treyka's gravatar image

treyka
1035
accept rate: 22%

Also, have a look here: http://answers.splunk.com/questions/947/splunking-my-checkpoint-firewall-logs/

(12 Apr '10, 08:43) treyka

Note: If you are installing it on 64-bit Debian linux you will also need the ia32 libs (run 'apt-get install ia32-libs') in addition to the other instructions.

link

answered 27 Jul '10, 17:36

rforsythe's gravatar image

rforsythe
111
accept rate: 0%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

Asked: 02 Feb '10, 14:59

Seen: 971 times

Last updated: 27 Jul '10, 22:49

Copyright © 2005-2012 Splunk Inc. All rights reserved.