I have managed to get Bro logs into Splunk, but even with the App/TA the data is still clunked together and not very searchable. I've seen a few props.conf files here and there but has anyone had success with any?
↧