- Subscribe to RSS Feed
- Mark Question as New
- Mark Question as Read
- Float this Question for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
What processor for Zeek logs via Splunk Forwarder
- Labels:
-
Apache Hadoop
-
Apache Metron
-
Apache MiNiFi
-
Apache NiFi
-
Cloudera Data Engineering (CDE)
-
Cloudera Data Platform (CDP)
-
Cloudera Data Science and Engineering
-
Cloudera DataFlow (CDF)
-
Cloudera Essentials
-
Cloudera Manager
-
Data Analytics Studio
-
Data Lifecycle Manager
-
Hortonworks Data Platform (HDP)
-
Manual Installation
-
MapReduce
-
NiFi Registry
-
Schema Registry
-
Training
Created ‎11-23-2020 06:52 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have Zeek logs being ingested and being sent to Splunk via a Splunk Forwarder. I want to be able to catch this also in NiFi to be able to do some extra stuff to it, but I cannot see it using the usual processors as I think it is because of it monitoring the zeek logs constantly, and pushing them across, so it might seem to NiFi that there is no end of the file. There are delimiters within the Zeek logs - { }, but I am wondering if anyone else has tried this before with any success, as it seems I am the only one wanting to be able to do this. Whether it is because of the logs being sent across via the Splunk Forwarder, or because of the way the Zeek(bro) logs being monitored.
Created ‎11-30-2020 09:09 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hello,
Have you tried with a syslog listener on Nifi side?
