Setting up Splunk/IronPort WSA

Posted by Ciddan on Server Fault See other posts from Server Fault or by Ciddan
Published on 2009-11-04T17:53:02Z Indexed on 2010/05/05 9:08 UTC
Read the original article Hit count: 503

Filed under:
|
|
|
|

Hello everyone!

I recently stumbled across Splunk 4 (by way of an advert on this very site...) and found that it had an "App" that's designed to work with Cisco IronPort WebSecurity and E-Mail Appliances! That's really awesome, because good IronPort reporting is something our IT-dept. is looking for.

Anyways - I'm totally lost on how to configure this thing. I've googled like a mad-man to find a guide or such like - but I haven't found anything.

Has anyone here set up IP / Splunk? Any tips/pointers?

Regards, Mikael Selander

© Server Fault or respective owner

Related posts about splunk

  • Running a reverse proxy in front of Splunk 4.x

    as seen on Server Fault - Search for 'Server Fault'
    So, I have previously installed Splunk 3.x behind a reverse proxy and downloaded the latest version (4.0.6 at time of typing) expecting it to be as easy to use as before. Sadly this was not the case. There appears to be some elements which are not being translated correctly through the reverse proxy… >>> More

  • Alternatives to Splunk?

    as seen on Server Fault - Search for 'Server Fault'
    I'm pretty impressed with Splunk, especially version 4. Pretty graphs, alerting (Enterprise only), and fast, accurate, searching. It's a great product. However, the cost just way too high to consider for full production use for our company. All we really need is to be able to index different logs… >>> More

  • Setting up Splunk/IronPort WSA

    as seen on Server Fault - Search for 'Server Fault'
    Hello everyone! I recently stumbled across Splunk 4 (by way of an advert on this very site...) and found that it had an "App" that's designed to work with Cisco IronPort WebSecurity and E-Mail Appliances! That's really awesome, because good IronPort reporting is something our IT-dept. is looking… >>> More

  • Thoughts on Free Splunk

    as seen on Server Fault - Search for 'Server Fault'
    I am considering implementing Splunk at my company but am leery about the financial investment. I noticed there is a free version of Splunk that seem to be good enough. Can anyone tell me if you are using the free version at your company? Do you find the free version to be adequate, or just a springboard… >>> More

  • Nagios vs Splunk

    as seen on Server Fault - Search for 'Server Fault'
    I am looking to implement log tracking at my current company. After some research it seems Nagios and Splunk are the two best options. I was wondering if there is a consensus with which is better. I understand that Splunk can be quite pricey if the non-free version is used. That being said I can… >>> More

Related posts about cisco