RSSAmplifier

*☆。゚juni's caramel tech café・゚*☆ · Jan 23, 2023

Splunk Forwarders with Multiple Indexes

0
Sign in to vote or save

This page cannot be shown here. You can still read it on the original site — the toolbar below keeps your place in the directory.

- Pre-requisites: 
 
 Have a working Splunk instance (Splunk Enterprise, in my case) to connect to. There are plenty of tuts for this online. 
 
 
 Have installed a universal forwarder on the endpoint that you want to monitor (see here, an excellent post which will get you most of the way through setting up Splunk to analyse Suricata & pfSense logs) 
 
 
 
…

Read on /posts/0/splunk-forwarder/

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.