<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SC4S, Properly Indexing Juniper Netscreen in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/SC4S-Properly-Indexing-Juniper-Netscreen/m-p/548842#M5643</link>
    <description>&lt;P&gt;I recently installed SC4S. For most logs it works as expected; however, it is improperly indexing Juniper Netscreen as osnix with sourctype: nix:syslog. I've tried adding a filter to identify specific IPs as netscreen but it did not work. Any assistance is appreciated&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Example Raw Log:&lt;BR /&gt;&lt;/STRONG&gt;&amp;lt;133&amp;gt;Apr 19 20:06:42 172.#.#.2/172.#.#.2 SC-NS1-SSG140: NetScreen device_id=SC-NS1-SSG140 [Root]system-notification-00257(traffic): start_time="2021-04-21 17:13:42" duration=0 policy_id=320001 service=tcp/port:8013 proto=6 src zone=Null dst zone=self action=Deny sent=0 rcvd=52 src=10.#.#.133 dst=10.#.#.1 src_port=53563 dst_port=8013 session_id=0 reason=Traffic Denied&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Splunk Results&lt;/STRONG&gt;&lt;BR /&gt;SC-NS1-SSG140: NetScreen device_id=SC-NS1-SSG140 [Root]system-notification-00257(traffic): start_time="2021-04-21 17:13:42" duration=0 policy_id=320001 service=tcp/port:8013 proto=6 src zone=Null dst zone=self action=Deny sent=0 rcvd=52 src=10.#.#.1 dst=10.#.#.133 src_port=53563 dst_port=8013 session_id=0 reason=Traffic Denied&lt;/P&gt;&lt;P&gt;host = 172.#.#.2/172..#.#.2&lt;BR /&gt;index = osnix&lt;BR /&gt;sc4s_fromhostip = 172.#.#.150&lt;BR /&gt;sc4s_syslog_facility = user&lt;BR /&gt;sc4s_syslog_format = rfc3164&lt;BR /&gt;sc4s_vendor_product = nix_syslog&lt;BR /&gt;source = program:SC-NS1-SSG140&lt;BR /&gt;sourcetype = nix:syslog&lt;/P&gt;</description>
    <pubDate>Wed, 21 Apr 2021 17:33:40 GMT</pubDate>
    <dc:creator>jorob</dc:creator>
    <dc:date>2021-04-21T17:33:40Z</dc:date>
    <item>
      <title>SC4S, Properly Indexing Juniper Netscreen</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/SC4S-Properly-Indexing-Juniper-Netscreen/m-p/548842#M5643</link>
      <description>&lt;P&gt;I recently installed SC4S. For most logs it works as expected; however, it is improperly indexing Juniper Netscreen as osnix with sourctype: nix:syslog. I've tried adding a filter to identify specific IPs as netscreen but it did not work. Any assistance is appreciated&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Example Raw Log:&lt;BR /&gt;&lt;/STRONG&gt;&amp;lt;133&amp;gt;Apr 19 20:06:42 172.#.#.2/172.#.#.2 SC-NS1-SSG140: NetScreen device_id=SC-NS1-SSG140 [Root]system-notification-00257(traffic): start_time="2021-04-21 17:13:42" duration=0 policy_id=320001 service=tcp/port:8013 proto=6 src zone=Null dst zone=self action=Deny sent=0 rcvd=52 src=10.#.#.133 dst=10.#.#.1 src_port=53563 dst_port=8013 session_id=0 reason=Traffic Denied&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Splunk Results&lt;/STRONG&gt;&lt;BR /&gt;SC-NS1-SSG140: NetScreen device_id=SC-NS1-SSG140 [Root]system-notification-00257(traffic): start_time="2021-04-21 17:13:42" duration=0 policy_id=320001 service=tcp/port:8013 proto=6 src zone=Null dst zone=self action=Deny sent=0 rcvd=52 src=10.#.#.1 dst=10.#.#.133 src_port=53563 dst_port=8013 session_id=0 reason=Traffic Denied&lt;/P&gt;&lt;P&gt;host = 172.#.#.2/172..#.#.2&lt;BR /&gt;index = osnix&lt;BR /&gt;sc4s_fromhostip = 172.#.#.150&lt;BR /&gt;sc4s_syslog_facility = user&lt;BR /&gt;sc4s_syslog_format = rfc3164&lt;BR /&gt;sc4s_vendor_product = nix_syslog&lt;BR /&gt;source = program:SC-NS1-SSG140&lt;BR /&gt;sourcetype = nix:syslog&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 17:33:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/SC4S-Properly-Indexing-Juniper-Netscreen/m-p/548842#M5643</guid>
      <dc:creator>jorob</dc:creator>
      <dc:date>2021-04-21T17:33:40Z</dc:date>
    </item>
  </channel>
</rss>

