Admin Manual

 


Authentication

Snare

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Snare

You can set up Splunk to search your Windows event logs in about 15 minutes.


Snare will now begin sending events to port 514 on your Splunk host via UDP.


Loading Snare Data into Splunk

There are a few different ways to get your Snare logs into Splunk. We recommend a FIFO as the fastest and most dynamic method. Use Splunk's syslogFIFO input module to load the events.


By default your Windows logs will be combined with other syslog events on your Splunk host. You can send the Windows event logs to Splunk through the same FIFO as your syslog events. However, you can take advantage of our correct custom typer to grab tags directly from Microsoft. In order to call this custom typer, you must send your Windows event logs through a separate FIFO to Splunk.


How you configure your FIFO depends on whether you are using syslog or syslog-ng.


External Links

This documentation applies to the following versions of Splunk: 2.1 , 2.2 , 2.2.1 , 2.2.3 , 2.2.6 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.