Quantcast
Channel: Questions in topic: "heavy-forwarder"
Viewing all articles
Browse latest Browse all 727

FireEye App for Splunk Enterprise v3: How to send FireEye alerts on the heavy forwarder to a custom index on an indexer?

$
0
0
Using TCP CEF Syslog to send FireEye alerts to our heavy forwarder, how do we get the events to forward to a custom index on the indexer? There is no inputs.conf within the app itself. All alerts are being forwarded to the main index currently. We have followed the instructions outlined on pg 18 of the document linked below, but this appears like it will only work for sending events via JSON HTTPS. PG 18. https://www.fireeye.com/content/dam/fireeye-www/global/en/partners/pdfs/config-guide-fireeye-app-for-splunk-enterprise.pdf Does anyone have experience with sending FireEye alerts from a forwarder to a custom index, and is this possible with tcp syslog cef?

Viewing all articles
Browse latest Browse all 727

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>