Troubleshoot the Splunk Add-on for Cisco FireSIGHT
General troubleshooting
For helpful troubleshooting tips that you can apply to all add-ons, see "Troubleshoot add-ons" in Splunk Add-ons. For additional resources, see "Support and resource links for add-ons" in Splunk Add-ons.
Data truncation issues
Data gathered with monitor inputs for the Splunk Add-on for Cisco FireSIGHT may not always perfectly match the expected props and transforms due to line-breaking or timestamp recognition configuration choices in inputs.conf
. Add-ons cannot predict all possible configuration scenarios, and some troubleshooting may be required to recognize and resolve an issue of this type.
If the last value of a line is not extracting properly or the event is broken strangely, try input level changes such as:
MAX_TIMESTAMP_LOOKAHEAD = 30
or
TIME_PREFIX=^
Review inputs.conf documentation for more background.
Configure inputs for the Splunk Add-on for Cisco FireSIGHT | Lookups for the Splunk Add-on for FireSIGHT |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!