Forwarding Snort Live Logs To Splunk.
To forward live snort logs to Splunk we need to follow 4 main step as below. 1) Splunk Port Configuration. 2) Firewall Setup. 3) Download Splunk Forwarder in Kali. 4) Step to forward snort live log to Splunk . 1)Splunk Port Configuration Step 1: - Go to https://www.127.0.0.1:8000 Step 2: - Click on Setting And Select "Add Data" And Then Select " Forwarding & Receiving ". Step 3:- In Receiving Data Click On " Configure Receiving ". Step 4:- And Add Port Number 9997. {9997 is Default Splunk Port Number} Now You Can See Successfully We Added Receiving Port . Step 5:- click on Apps and then select on "Find More Apps" . Step 6:- search snort and then install "Snort Alert For Splunk". step 7:- It will ask you to username and password use same username and password as Splunk, and then click on "Login and Install". 2)Firewall Setup Step 1:- Then Go To Windows Control Panel and Open Windows Firewall. ...