Posts

Showing posts with the label Snort logs to Splunk

Forwarding Snort Live Logs To Splunk.

Image
To forward live snort logs to Splunk we need to follow 4 main step as below. 1) Splunk Port Configuration. 2) Firewall Setup. 3) Download Splunk Forwarder in Kali. 4) Step to forward snort live log to Splunk . 1)Splunk Port Configuration Step 1: - Go to https://www.127.0.0.1:8000 Step 2: - Click on Setting And Select "Add Data" And Then Select " Forwarding & Receiving ".   Step 3:- In Receiving Data Click On " Configure Receiving ".   Step 4:- And Add Port Number 9997.            {9997 is Default Splunk Port Number} Now You Can See Successfully We Added Receiving Port . Step 5:- click on Apps and then select on "Find More Apps" .   Step 6:- search snort and then install "Snort Alert For Splunk". step 7:- It will ask you to username and password use same username and password as  Splunk,  and then click on "Login and Install". 2)Firewall Setup Step 1:- Then Go To Windows Control Panel and Open Windows Firewall. ...