Snort mailing list archives
snort -> barnyard2 -> splunk
From: Robert Millott <robm () millottandassociates com>
Date: Wed, 27 Aug 2014 16:15:49 -0400
Anyone have some good suggestions on getting Snort into Splunk? I've seen some directions for snort -> barnyard2 -> syslog -> syslog-ng -> splunk, but I don't see the need for syslog. I've also seen snort -> splunk via alert_fast, but I already have barnyard2, and from what I hear, using barnyard2 will help optimize snort by relieveing some of the processing it must do. Can barnyard2 send directly to splunk in a format splunk will understand is originally snort data? -- Robert Millott President, Millott and Associates (443) 255-3588
------------------------------------------------------------------------------ Slashdot TV. Video for Nerds. Stuff that matters. http://tv.slashdot.org/
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users Please visit http://blog.snort.org to stay current on all the latest Snort news!
Current thread:
- snort -> barnyard2 -> splunk Robert Millott (Aug 27)
- Re: snort -> barnyard2 -> splunk Shirkdog (Aug 27)
- Re: snort -> barnyard2 -> splunk VM PC (Aug 27)