<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Onboard Unknown Source to SC4S in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Onboard-Unknown-Source-to-SC4S/m-p/754777#M119791</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313603"&gt;@loz&lt;/a&gt;&amp;nbsp;there is no need to create a default parser for this as the CEF parser exists. You simply need to redirect the data using the&amp;nbsp;&lt;SPAN&gt;splunk_metadata.csv file as per the example here:&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunk.github.io/splunk-connect-for-syslog/main/sources/base/cef/#splunk-metadata-with-cef-events" target="_blank"&gt;https://splunk.github.io/splunk-connect-for-syslog/main/sources/base/cef/#splunk-metadata-with-cef-events&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Oct 2025 08:23:11 GMT</pubDate>
    <dc:creator>phanTom</dc:creator>
    <dc:date>2025-10-27T08:23:11Z</dc:date>
    <item>
      <title>Onboard Unknown Source to SC4S</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Onboard-Unknown-Source-to-SC4S/m-p/754321#M119742</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;We are attempting to onboard Defender for IOT on prem sensor logs to SC4S.&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are currently being sent over port 514 in CEF format and have been written to the default config of the main index and cef sourcetype.&lt;/P&gt;&lt;P&gt;We have attempted to write a custom parser based on the example in the docs, to send the logs to our defined index and sourcetype.&amp;nbsp;&lt;A href="https://splunk.github.io/splunk-connect-for-syslog/main/create-parser/" target="_blank" rel="noopener"&gt;(https://splunk.github.io/splunk-connect-for-syslog/main/create-parser/.&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;Are there any other steps we are missing?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2025 22:59:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Onboard-Unknown-Source-to-SC4S/m-p/754321#M119742</guid>
      <dc:creator>loz</dc:creator>
      <dc:date>2025-10-14T22:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: Onboard Unknown Source to SC4S</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Onboard-Unknown-Source-to-SC4S/m-p/754777#M119791</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/313603"&gt;@loz&lt;/a&gt;&amp;nbsp;there is no need to create a default parser for this as the CEF parser exists. You simply need to redirect the data using the&amp;nbsp;&lt;SPAN&gt;splunk_metadata.csv file as per the example here:&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunk.github.io/splunk-connect-for-syslog/main/sources/base/cef/#splunk-metadata-with-cef-events" target="_blank"&gt;https://splunk.github.io/splunk-connect-for-syslog/main/sources/base/cef/#splunk-metadata-with-cef-events&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2025 08:23:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Onboard-Unknown-Source-to-SC4S/m-p/754777#M119791</guid>
      <dc:creator>phanTom</dc:creator>
      <dc:date>2025-10-27T08:23:11Z</dc:date>
    </item>
  </channel>
</rss>

