Skip to main content
Warning
This app is archived. App archiving documentation
Ubiquiti add-on for Splunk app icon

Ubiquiti add-on for Splunk

The TA for Ubiquiti was developed on an environment with CloudKey, USG, USG-Pro and Pro AP. It contains field extractions for the Firewall, DHCP and beta IPS facilities. There are other source-types in this add-on which I have not been able to create the field extractions for, since they are cryptic. I am in contact with Ubiquiti's support to find out more information. Should you have this information please feel free to reach out.Built by Filip Wijnholds
splunk product badge

Default Version 1.3.6

May 9, 2022

Compatibility

Splunk Enterprise

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 5.x, 4.x

Rating
4
(9)

Log in to rate this app

Support
Archived Add-on

The TA for Ubiquiti was developed on an environment with CloudKey, USG, USG-Pro and Pro AP. It contains field extractions for the Firewall, DHCP and beta IPS facilities. There are other source-types in this add-on which I have not been able to create the field extractions for, since they are cryptic. I am in contact with Ubiquiti's support to find out more information. Should you have this information please feel free to reach out. To make this TA work fully CIM compliant follow the instructions on routing the different Sourcetypes to their individual indexes. If you would like to contribute I've opened the repo: https://github.com/fwijnholds/TA-ubiquiti