|
Is Splunk 4.x able to eat messages in OPSEC formatted style? Are we able to read it in a human readable form via Splunk Search? |
|
Yes. In order to index OPSEC data you will need to have an LEA server and then configure Splunk to fetch the data from there. Instructions and binaries for enabling this can be found on in the Community Wiki. Note this solution is only supported on Linux and Solaris |
|
Simon - Have a look at the discussion page on the community wiki as well, there are some potentially helpful caveats there. Also, have a look here: http://answers.splunk.com/questions/947/splunking-my-checkpoint-firewall-logs/
(12 Apr '10, 08:43)
treyka
|