Quantcast
Channel: Questions in topic: "props.conf"
Viewing all articles
Browse latest Browse all 1485

Splunk TA for Suricata: Should TIME_PREFIX=event_second": be changed to TIME_PREFIX=timestamp": in props.conf?

$
0
0
Our suri nodes have "timestamp" as a prefix for {"timestamp":"2016-02-29T10:11:26.037993+0100", "flow_id":140671543700208, "in_iface":"etthxxx", "event_type":"alert", "src_ip":"198.51.44.3", "src_port":53, ... .. Has this changed recently? If so, it might be worth updating the app to something like: cat TA-Suricata/default/props.conf [post_suricata_eve] SHOULD_LINEMERGE = true TIME_PREFIX=timestamp": BREAK_ONLY_BEFORE = ^{ KV_MODE = json Regards Chris

Viewing all articles
Browse latest Browse all 1485

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>