<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Syslog from multiple devices in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-multiple-devices/m-p/105419#M22210</link>
    <description>&lt;P&gt;I have riverbed 10.10.10.1 and barracuda 10.10.10.2 both writing syslog (on UDP 514 which I cannot change) to my Splunk server&lt;/P&gt;

&lt;P&gt;all was well when I just had barracuda data as I set a manual UDP data input&lt;/P&gt;

&lt;P&gt;UDP 514 sourcetype barracuda&lt;/P&gt;

&lt;P&gt;but now I ALSO need a UDP 514 sourcetype riverbed_steelhead&lt;/P&gt;

&lt;P&gt;I dont have resource to set up another product to split these in advance of arriving on the Splunk server&lt;/P&gt;

&lt;P&gt;any help would really be appreciated&lt;/P&gt;</description>
    <pubDate>Wed, 24 Apr 2013 16:49:42 GMT</pubDate>
    <dc:creator>7070ithelpdesk</dc:creator>
    <dc:date>2013-04-24T16:49:42Z</dc:date>
    <item>
      <title>Syslog from multiple devices</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-multiple-devices/m-p/105419#M22210</link>
      <description>&lt;P&gt;I have riverbed 10.10.10.1 and barracuda 10.10.10.2 both writing syslog (on UDP 514 which I cannot change) to my Splunk server&lt;/P&gt;

&lt;P&gt;all was well when I just had barracuda data as I set a manual UDP data input&lt;/P&gt;

&lt;P&gt;UDP 514 sourcetype barracuda&lt;/P&gt;

&lt;P&gt;but now I ALSO need a UDP 514 sourcetype riverbed_steelhead&lt;/P&gt;

&lt;P&gt;I dont have resource to set up another product to split these in advance of arriving on the Splunk server&lt;/P&gt;

&lt;P&gt;any help would really be appreciated&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2013 16:49:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-multiple-devices/m-p/105419#M22210</guid>
      <dc:creator>7070ithelpdesk</dc:creator>
      <dc:date>2013-04-24T16:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog from multiple devices</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-multiple-devices/m-p/105420#M22211</link>
      <description>&lt;P&gt;In props.conf, set sourcetype by Host IP.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[host::10.10.10.1]&lt;BR /&gt;
sourcetype=barracuda&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[host::10.10.10.2]&lt;BR /&gt;
sourcetype=riverbed_steelhead&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/admin/propsconf" target="test_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/admin/propsconf&lt;/A&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2013 17:11:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-multiple-devices/m-p/105420#M22211</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2013-04-24T17:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog from multiple devices</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-multiple-devices/m-p/105421#M22212</link>
      <description>&lt;P&gt;Thanks for this&lt;/P&gt;

&lt;P&gt;I have quite a few apps installed and each seems to have its own "props.conf" (31 in total) when I seach the Splunk top level folder&lt;/P&gt;

&lt;P&gt;I assume the entry has to be in the "main" props.conf&lt;/P&gt;

&lt;P&gt;Could you tell me which one to edit&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2013 09:39:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-multiple-devices/m-p/105421#M22212</guid>
      <dc:creator>7070ithelpdesk</dc:creator>
      <dc:date>2013-04-25T09:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog from multiple devices</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-multiple-devices/m-p/105422#M22213</link>
      <description>&lt;P&gt;I added the sourcetypes below in the props.conf in the folder&lt;/P&gt;

&lt;P&gt;C:\Program Files\Splunk\etc\system\default&lt;/P&gt;

&lt;P&gt;I then set my UDP 514 input back to the default syslog &lt;/P&gt;

&lt;P&gt;an I get no data from my Barracuda&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2013 09:42:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-multiple-devices/m-p/105422#M22213</guid>
      <dc:creator>7070ithelpdesk</dc:creator>
      <dc:date>2013-04-25T09:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog from multiple devices</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-multiple-devices/m-p/105423#M22214</link>
      <description>&lt;P&gt;I have tried this solution for my problem.&lt;/P&gt;

&lt;P&gt;I've set up UDP 514 for sourcetype cisco:asa (most of the syslog hosts are cisco asa's).&lt;BR /&gt;
But I need syslog for different sourcetypes like cisco:esa:textmail and McAfee Firewall Enterprise (Sidewinder) etc.&lt;/P&gt;

&lt;P&gt;I've set up a blank props.conf with the following syntax:&lt;BR /&gt;
[host::10.1.1.2] sourcetype = cisco.esa.textmail&lt;BR /&gt;
[host::10.1.1.1] sourcetype = cisco.esa.textmail&lt;/P&gt;

&lt;P&gt;But in the search app the sourcetype is still cisco:asa.&lt;/P&gt;

&lt;P&gt;What do I have to do additionally?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2015 08:57:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-multiple-devices/m-p/105423#M22214</guid>
      <dc:creator>MOberschelp</dc:creator>
      <dc:date>2015-02-24T08:57:46Z</dc:date>
    </item>
  </channel>
</rss>

