Splunk and Shibboleth

Grinnell, Michael (mg7aa) grinnell at virginia.edu
Tue May 24 14:30:25 UTC 2022


Does anyone have a good Splunk field extraction regex for Shibboleth 4 logs?  The "official" Shibboleth add-on appears to no longer be supported by Splunk.  I found these when looking around, but they are really old and incomplete, at least for our logs.  

https://splunkbase.splunk.com/app/4389/ - created at request of the Net+ Splunk group, but apparently discontinued.

https://community.splunk.com/t5/Monitoring-Splunk/splunk-and-shibboleth-log-analysis/m-p/155695

Thanks,

Michael (he/him/his <https://pronoun.is/he>)







More information about the users mailing list