*☆。゚juni's caramel tech café・゚*☆ · Jan 23, 2023
Splunk Forwarders with Multiple Indexes
0Sign in to vote or save
This page cannot be shown here. You can still read it on the original site — the toolbar below keeps your place in the directory.
- Pre-requisites: 
 
 Have a working Splunk instance (Splunk Enterprise, in my case) to connect to. There are plenty of tuts for this online. 
 
 
 Have installed a universal forwarder on the endpoint that you want to monitor (see here, an excellent post which will get you most of the way through setting up Splunk to analyse Suricata & pfSense logs) 
 
 
 
…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.