<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog Configuration required for custom sourcetypes in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/745596#M118508</link>
    <description>&lt;P&gt;The following link provides the common format for CEF log format, assuming that's your format.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://splunk.github.io/splunk-connect-for-syslog/main/sources/base/cef/#splunk-metadata-with-cef-events" target="_blank"&gt;https://splunk.github.io/splunk-connect-for-syslog/main/sources/base/cef/#splunk-metadata-with-cef-events&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 06 May 2025 21:38:05 GMT</pubDate>
    <dc:creator>dionrivera</dc:creator>
    <dc:date>2025-05-06T21:38:05Z</dc:date>
    <item>
      <title>Syslog Configuration required for custom sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/745094#M118451</link>
      <description>&lt;P&gt;I think Splunk doesn't have a built-in/defined sourcetype for ExtremeCloud XIQ logs. Can we define a custom sourcetype, like `extremecloud:xiq`, in the syslog server(splunk_metadata.csv)? If so, how do we make sure the logs coming from ExtremeCloud XIQ platform land in the "extreme" index and use the "extremecloud:xiq" sourcetype?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 11:32:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/745094#M118451</guid>
      <dc:creator>msatish</dc:creator>
      <dc:date>2025-04-28T11:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Configuration required for custom sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/745096#M118452</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/275655"&gt;@msatish&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to confirm - are you using SC4S?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not familiar with&amp;nbsp;&lt;SPAN&gt;ExtremeCloud XIQ and it isnt a "known product" to SC4S however we should still be able to update splunk_metadata.csv.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you know if the data is being sent in CEF format? If possible please could you provide a couple of lines of your events to help us work out the correct values for the splunk_metadata.csv file?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 11:55:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/745096#M118452</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-28T11:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Configuration required for custom sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/745147#M118453</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/275655"&gt;@msatish&lt;/a&gt;- Yes you can always define your own sourcetype &amp;amp; your own custom index that you want any data to fall into.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But as &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt; is asking you can need to figure-out how you are collecting the data &amp;amp; which format of the logs so you can figure-out from which config file &amp;amp; where you can apply the new sourcetype &amp;amp; index. And you also need to put props.conf configuration (Parsing, Timestamp extraction, Field Extraction, etc.) for your custom sourcetype.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And make sure index is created on your indexers before you start pushing the data into your custom index.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 06:05:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/745147#M118453</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2025-04-29T06:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Configuration required for custom sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/745596#M118508</link>
      <description>&lt;P&gt;The following link provides the common format for CEF log format, assuming that's your format.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://splunk.github.io/splunk-connect-for-syslog/main/sources/base/cef/#splunk-metadata-with-cef-events" target="_blank"&gt;https://splunk.github.io/splunk-connect-for-syslog/main/sources/base/cef/#splunk-metadata-with-cef-events&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 May 2025 21:38:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/745596#M118508</guid>
      <dc:creator>dionrivera</dc:creator>
      <dc:date>2025-05-06T21:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Configuration required for custom sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/745597#M118509</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The following link provides the common format for CEF log format, assuming that's your format.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://splunk.github.io/splunk-connect-for-syslog/main/sources/base/cef/#splunk-metadata-with-cef-events" target="_blank" rel="nofollow noopener noreferrer"&gt;https://splunk.github.io/splunk-connect-for-syslog/main/sources/base/cef/#splunk-metadata-with-cef-e...&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 May 2025 21:38:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/745597#M118509</guid>
      <dc:creator>dionrivera</dc:creator>
      <dc:date>2025-05-06T21:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Configuration required for custom sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/747256#M118749</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes, logs needs to be forwarded to SC4S. ExtremeCloud IQ will be sending logs in the legacy SYSLOG format RFC3164. Can we use app parser configuration file on the syslog server where we plan to receive Extreme AP logs in the legacy SYSLOG format RFC3164. Will this help in normalizing the data received from Extreme AP when tweaked as per log sample .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here is the resource I am referring to:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A title="https://splunk.github.io/splunk-connect-for-syslog/main/sources/" href="https://splunk.github.io/splunk-connect-for-syslog/main/sources/" target="_blank" rel="noreferrer noopener"&gt;https://splunk.github.io/splunk-connect-for-syslog/main/sources/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, should we need an add on or app to be installed or just defining app_parser conf file in Syslog help ?&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 09:34:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/747256#M118749</guid>
      <dc:creator>msatish</dc:creator>
      <dc:date>2025-05-30T09:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Configuration required for custom sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/748089#M118884</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp;/&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;A title="https://apps.splunk.com/app/1780/" href="https://apps.splunk.com/app/1780/" target="_blank" rel="noreferrer noopener"&gt;https://apps.splunk.com/app/1780/&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;-Does this EXOS app still help in parsing? or is it outdated one? &lt;SPAN&gt;&amp;nbsp;Is EXOS an Extreme old operating system?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 09:45:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/748089#M118884</guid>
      <dc:creator>msatish</dc:creator>
      <dc:date>2025-06-17T09:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Configuration required for custom sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/748288#M118922</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/275655"&gt;@msatish&lt;/a&gt;&amp;nbsp;- As mentioned by&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/66553"&gt;@dionrivera&lt;/a&gt;&amp;nbsp;you can use SC4S CEF for parsing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if you want to parse the already ingested CEF formatted data in Splunk then you can use this App's custom search command to do that.&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/7701" target="_blank"&gt;https://splunkbase.splunk.com/app/7701&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jun 2025 05:14:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-Configuration-required-for-custom-sourcetypes/m-p/748288#M118922</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2025-06-19T05:14:02Z</dc:date>
    </item>
  </channel>
</rss>

