--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-net...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/b6d55239-00e7-4972-96c8-e4d9d386c284%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsub...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/b6d55239-00e7-4972-96c8-e4d9d386c284%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
I have tried everything I know possible and really want to find a solution as I love MHN and all the intelligence I am gathering.
Please help.
Thanks.
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsub...@googlegroups.com.
To post to this group, send email to modern-honey-network@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/51c1c07d-ddf1-4463-a77d-8a2805055872%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
MHN server is linux box and Splunk enterprise is in a Windows box.
MHN server is a droplet, I am able to SFTP the MHN-Splunk log and upload to Splunk but I would like it in real time and automated.
I have no Splunk log in the location you mentioned just the Splunkforwarder is in /opt
Thanks for the quick reply.
Is your Splunk box listening on 9997? Is there a firewall or web proxy blocking traffic to this port?I recommend looking at the logs in /opt/splunk/var/logs to see if you can identify what is going wrong.
On Wed, Nov 16, 2016 at 11:33 PM, <ambient...@gmail.com> wrote:
I have this same issue but my MHN server and Splunk are on two separate boxes. Events are in mhn-splunk.log. 9997 set to receive in splunk but nothing is showing up in the MHN Splunk app.
I have tried everything I know possible and really want to find a solution as I love MHN and all the intelligence I am gathering.
Please help.
Thanks.
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsub...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/51c1c07d-ddf1-4463-a77d-8a2805055872%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Is your Splunk box listening on 9997? Is there a firewall or web proxy blocking traffic to this port?I recommend looking at the logs in /opt/splunk/var/logs to see if you can identify what is going wrong.
On Wed, Nov 16, 2016 at 11:33 PM, <ambient...@gmail.com> wrote:
I have this same issue but my MHN server and Splunk are on two separate boxes. Events are in mhn-splunk.log. 9997 set to receive in splunk but nothing is showing up in the MHN Splunk app.
I have tried everything I know possible and really want to find a solution as I love MHN and all the intelligence I am gathering.
Please help.
Thanks.
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsub...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/51c1c07d-ddf1-4463-a77d-8a2805055872%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Is your Splunk box listening on 9997? Is there a firewall or web proxy blocking traffic to this port?I recommend looking at the logs in /opt/splunk/var/logs to see if you can identify what is going wrong.
On Wed, Nov 16, 2016 at 11:33 PM, <ambient...@gmail.com> wrote:
I have this same issue but my MHN server and Splunk are on two separate boxes. Events are in mhn-splunk.log. 9997 set to receive in splunk but nothing is showing up in the MHN Splunk app.
I have tried everything I know possible and really want to find a solution as I love MHN and all the intelligence I am gathering.
Please help.
Thanks.
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsub...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/51c1c07d-ddf1-4463-a77d-8a2805055872%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Sorry for so many replies but I am very determined.I tried the following from MHN server to Windows (Splunk):telnet <indexer_ip> <indexer port>Unable to connect to remote host: Connection timed out. Not sure at this point because.
On Thursday, November 17, 2016 at 10:30:59 AM UTC-8, Jason Trost wrote:
Is your Splunk box listening on 9997? Is there a firewall or web proxy blocking traffic to this port?I recommend looking at the logs in /opt/splunk/var/logs to see if you can identify what is going wrong.
On Wed, Nov 16, 2016 at 11:33 PM, <ambient...@gmail.com> wrote:
I have this same issue but my MHN server and Splunk are on two separate boxes. Events are in mhn-splunk.log. 9997 set to receive in splunk but nothing is showing up in the MHN Splunk app.
I have tried everything I know possible and really want to find a solution as I love MHN and all the intelligence I am gathering.
Please help.
Thanks.
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsubscrib...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/51c1c07d-ddf1-4463-a77d-8a2805055872%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--Jason Trost | VP of Threat Research | www.anomali.com2317 Broadway, 3rd Floor| Redwood City, CA 94063Phone: 386.235.0078 | Twitter: @jason_trost
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsub...@googlegroups.com.
To post to this group, send email to modern-honey-network@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/9e8b9ba8-2afd-4d82-857d-e1c787a30f94%40googlegroups.com.
Check to see if splunk is listening on that port on all interfaces (or just the local interface):What is the output of this command on your splunk box?sudo netstat -luntp | grep splunk
On Thu, Nov 17, 2016 at 6:19 PM, <ambient...@gmail.com> wrote:
Sorry for so many replies but I am very determined.I tried the following from MHN server to Windows (Splunk):telnet <indexer_ip> <indexer port>Unable to connect to remote host: Connection timed out. Not sure at this point because.
On Thursday, November 17, 2016 at 10:30:59 AM UTC-8, Jason Trost wrote:
Is your Splunk box listening on 9997? Is there a firewall or web proxy blocking traffic to this port?I recommend looking at the logs in /opt/splunk/var/logs to see if you can identify what is going wrong.
On Wed, Nov 16, 2016 at 11:33 PM, <ambient...@gmail.com> wrote:
I have this same issue but my MHN server and Splunk are on two separate boxes. Events are in mhn-splunk.log. 9997 set to receive in splunk but nothing is showing up in the MHN Splunk app.
I have tried everything I know possible and really want to find a solution as I love MHN and all the intelligence I am gathering.
Please help.
Thanks.
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsub...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/51c1c07d-ddf1-4463-a77d-8a2805055872%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--Jason Trost | VP of Threat Research | www.anomali.com2317 Broadway, 3rd Floor| Redwood City, CA 94063Phone: 386.235.0078 | Twitter: @jason_trost
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsub...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/9e8b9ba8-2afd-4d82-857d-e1c787a30f94%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsubscrib...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/51c1c07d-ddf1-4463-a77d-8a2805055872%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--Jason Trost | VP of Threat Research | www.anomali.com2317 Broadway, 3rd Floor| Redwood City, CA 94063Phone: 386.235.0078 | Twitter: @jason_trost
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsubscrib...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/9e8b9ba8-2afd-4d82-857d-e1c787a30f94%40googlegroups.com.
--Jason Trost | VP of Threat Research | www.anomali.com2317 Broadway, 3rd Floor| Redwood City, CA 94063Phone: 386.235.0078 | Twitter: @jason_trost
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsub...@googlegroups.com.
To post to this group, send email to modern-honey-network@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/69a1601e-8a42-444c-a2fe-22e3d6f4763e%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsub...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/51c1c07d-ddf1-4463-a77d-8a2805055872%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--Jason Trost | VP of Threat Research | www.anomali.com2317 Broadway, 3rd Floor| Redwood City, CA 94063Phone: 386.235.0078 | Twitter: @jason_trost
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsub...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/9e8b9ba8-2afd-4d82-857d-e1c787a30f94%40googlegroups.com.
--Jason Trost | VP of Threat Research | www.anomali.com2317 Broadway, 3rd Floor| Redwood City, CA 94063Phone: 386.235.0078 | Twitter: @jason_trost
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsub...@googlegroups.com.
To post to this group, send email to modern-honey-network@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/69a1601e-8a42-444c-a2fe-22e3d6f4763e%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsubscrib...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/51c1c07d-ddf1-4463-a77d-8a2805055872%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--Jason Trost | VP of Threat Research | www.anomali.com2317 Broadway, 3rd Floor| Redwood City, CA 94063Phone: 386.235.0078 | Twitter: @jason_trost
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsubscrib...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/9e8b9ba8-2afd-4d82-857d-e1c787a30f94%40googlegroups.com.
--Jason Trost | VP of Threat Research | www.anomali.com2317 Broadway, 3rd Floor| Redwood City, CA 94063Phone: 386.235.0078 | Twitter: @jason_trost
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsubscrib...@googlegroups.com.
To post to this group, send email to modern-honey-network@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/69a1601e-8a42-444c-a2fe-22e3d6f4763e%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--Jason Trost | VP of Threat Research | www.anomali.com2317 Broadway, 3rd Floor| Redwood City, CA 94063Phone: 386.235.0078 | Twitter: @jason_trost
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsub...@googlegroups.com.
To post to this group, send email to modern-honey-network@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/84453c41-9c47-472b-ad0b-999b78437281%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.