<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reporting only one unique device in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289869#M34550</link>
    <description>&lt;P&gt;cisco:ios &lt;/P&gt;</description>
    <pubDate>Wed, 05 Jul 2017 17:23:07 GMT</pubDate>
    <dc:creator>cboillot</dc:creator>
    <dc:date>2017-07-05T17:23:07Z</dc:date>
    <item>
      <title>Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289863#M34544</link>
      <description>&lt;P&gt;The dashboard is only showing me that I have 1 unique device. Digging into it, It looks like it is seeing the syslog server as the only device. I notice that some of the fields do have a "reported_hostname" field. How do I get those entries have have this to show this as the host field?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 15:24:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289863#M34544</guid>
      <dc:creator>cboillot</dc:creator>
      <dc:date>2017-07-05T15:24:16Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289864#M34545</link>
      <description>&lt;P&gt;please provide more info, what kind of devices are those?&lt;BR /&gt;
are you using any of the pre-built splunk apps?&lt;BR /&gt;
also might be related to how you write data to syslog &lt;BR /&gt;
hope it slightly helps&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 16:19:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289864#M34545</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-07-05T16:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289865#M34546</link>
      <description>&lt;P&gt;several different kinds. we have routers, switches, ASAs, ect.&lt;/P&gt;

&lt;P&gt;We are using the "Cisco Networks App for Splunk Enterprise" and the "Splunk Add-on for Cisco Networks"&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 16:51:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289865#M34546</guid>
      <dc:creator>cboillot</dc:creator>
      <dc:date>2017-07-05T16:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289866#M34547</link>
      <description>&lt;P&gt;how do you bring the data from syslog to splunk? universal forwarder? directly over TCP / UDP?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 17:07:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289866#M34547</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-07-05T17:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289867#M34548</link>
      <description>&lt;P&gt;universal forwarder&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 17:14:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289867#M34548</guid>
      <dc:creator>cboillot</dc:creator>
      <dc:date>2017-07-05T17:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289868#M34549</link>
      <description>&lt;P&gt;what is the sourcetype you have under your inputs stanza?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 17:16:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289868#M34549</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-07-05T17:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289869#M34550</link>
      <description>&lt;P&gt;cisco:ios &lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 17:23:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289869#M34550</guid>
      <dc:creator>cboillot</dc:creator>
      <dc:date>2017-07-05T17:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289870#M34551</link>
      <description>&lt;P&gt;do you have the TA installed?&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/1467/#/details"&gt;https://splunkbase.splunk.com/app/1467/#/details&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 17:38:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289870#M34551</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-07-05T17:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289871#M34552</link>
      <description>&lt;P&gt;Yes, it is showing as being installed. Version 2.3.4.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 19:10:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289871#M34552</guid>
      <dc:creator>cboillot</dc:creator>
      <dc:date>2017-07-05T19:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289872#M34553</link>
      <description>&lt;P&gt;can you kindly share your inputs.conf on the forwarder?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 01:29:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289872#M34553</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-07-06T01:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289873#M34554</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;[default]
ignoreOlderThan = 10d
blacklist = \.(gz|bz2|z|zip)$
recursive = false
index = main

[monitor:///var/agency_logs/AgencySyslog]
sourcetype=cisco:ios
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 06 Jul 2017 13:29:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289873#M34554</guid>
      <dc:creator>cboillot</dc:creator>
      <dc:date>2017-07-06T13:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289874#M34555</link>
      <description>&lt;P&gt;are all devices placing their data in one folder, AgencySyslog?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 17:21:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289874#M34555</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-07-06T17:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289875#M34556</link>
      <description>&lt;P&gt;They are all placing their data into the single file AgencySyslog.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2017 20:47:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289875#M34556</guid>
      <dc:creator>cboillot</dc:creator>
      <dc:date>2017-07-06T20:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289876#M34557</link>
      <description>&lt;P&gt;i believe this link will l be helpful:&lt;BR /&gt;
&lt;A href="https://www.splunk.com/blog/2016/03/11/using-syslog-ng-with-splunk.html"&gt;https://www.splunk.com/blog/2016/03/11/using-syslog-ng-with-splunk.html&lt;/A&gt;&lt;BR /&gt;
worthwhile to look at those as well:&lt;BR /&gt;
&lt;A href="http://www.georgestarcher.com/splunk-success-with-syslog/"&gt;http://www.georgestarcher.com/splunk-success-with-syslog/&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://www.function1.com/2012/05/syslog-collection-with-splunk"&gt;https://www.function1.com/2012/05/syslog-collection-with-splunk&lt;/A&gt;&lt;BR /&gt;
hope it helps&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 01:06:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289876#M34557</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-07-07T01:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289877#M34558</link>
      <description>&lt;P&gt;I will pass this information along and see what happens. Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2017 13:47:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289877#M34558</guid>
      <dc:creator>cboillot</dc:creator>
      <dc:date>2017-07-10T13:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289878#M34559</link>
      <description>&lt;P&gt;so, they redid the directories and now we have this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/var/agency_logs/cisco/ios/&amp;lt;hostname&amp;gt;/&amp;lt;syslogfacility-text&amp;gt;/&amp;lt;syslogseverity-text&amp;gt;/&amp;lt;year-month-day&amp;gt;.log
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and I have that entered in as &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///var/agency_logs/cisco/ios/*/local7/*/*.log]
host_segment = 5
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, these are not being pulled in for some reason.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 15:19:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289878#M34559</guid>
      <dc:creator>cboillot</dc:creator>
      <dc:date>2017-07-13T15:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289879#M34560</link>
      <description>&lt;P&gt;try this:&lt;BR /&gt;
    [monitor:///var/agency_logs/cisco/ios/.../local7/.../*.log]&lt;BR /&gt;
     host_segment = 5&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:52:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289879#M34560</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2020-09-29T14:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289880#M34561</link>
      <description>&lt;P&gt;Done. But it still isn't pulling the data in.&lt;/P&gt;

&lt;P&gt;here is my &lt;CODE&gt;inputs.conf&lt;/CODE&gt; file:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]

ignoreOlderThan = 10d
blacklist = \.(gz|bz2|z|zip)$
recursive = false
index = main
# index = enterprise_90days
sourcetype = cisco:ios
crcSalt = &amp;lt;SOURCE&amp;gt;

# Windows platform specific input processor.

[monitor:///var/agency_logs/cisco/ios/.../local7/.../*.log]
host_segment = 5

# [monitor:///var/agency_logs/AgencySyslogWLC]

# [monitor:///var/agency_logs/AgencySyslog]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 13 Jul 2017 16:28:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289880#M34561</guid>
      <dc:creator>cboillot</dc:creator>
      <dc:date>2017-07-13T16:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289881#M34562</link>
      <description>&lt;P&gt;can you double check the full path to file and compare with examples here:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Data/Specifyinputpathswithwildcards"&gt;https://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Data/Specifyinputpathswithwildcards&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2017 16:38:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289881#M34562</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-07-13T16:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: Reporting only one unique device</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289882#M34563</link>
      <description>&lt;P&gt;So I fixed my issue. I took the &lt;CODE&gt;local7&lt;/CODE&gt; out of the monitor stanza, and, this is the most important change, I changed &lt;CODE&gt;recursive&lt;/CODE&gt; to true.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2017 16:52:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Reporting-only-one-unique-device/m-p/289882#M34563</guid>
      <dc:creator>cboillot</dc:creator>
      <dc:date>2017-07-19T16:52:52Z</dc:date>
    </item>
  </channel>
</rss>

