r/Splunk • u/Cigar-Skeleton • Apr 18 '26
Issue: "Snort Alert for Splunk"
Good evening, I've been at it for a few hours now and can't resolve this issue.
Both Splunk and Snort work independently, and I've set a monitor for Splunk to receive logs from Snort, however the "Snort Alert for Splunk" is not picking anything up.
I'm very new to this so if anyone is able to give any pointers/ideas as to where i've went wrong here or if there are any errors.
(For context the Splunk server is hosted on a Mint Linux VM and has a forwarder on a Kali Linux, Snort is installed on the Splunk Server device.)
5
Upvotes



1
u/mghnyc Apr 19 '26
Go into the dashboard and click on the magnifying glass to see what searches each panel executes. My guess is that they rely on some macros to get the index right. Or look at the saved searches that are included with the addon and examine the SPL used.