[Snort-users] snort -> barnyard2 -> splunk
robm at ...16885...
Wed Aug 27 16:15:49 EDT 2014
Anyone have some good suggestions on getting Snort into Splunk? I've seen
some directions for snort -> barnyard2 -> syslog -> syslog-ng -> splunk,
but I don't see the need for syslog. I've also seen snort -> splunk via
alert_fast, but I already have barnyard2, and from what I hear, using
barnyard2 will help optimize snort by relieveing some of the processing it
Can barnyard2 send directly to splunk in a format splunk will understand is
originally snort data?
President, Millott and Associates
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Snort-users