<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: If I have multiple Cisco devices sending syslog directly to Splunk with the same source and sourcetype, how do I view them separately? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/If-I-have-multiple-Cisco-devices-sending-syslog-directly-to/m-p/180479#M36203</link>
    <description>&lt;P&gt;This is most likely because all of your devices are sending to the UDP input on the Splunk server, and you have that UDP input configured as cisco:asa. There are a few options to change this:&lt;/P&gt;

&lt;P&gt;1) Create different UDP inputs for each device type:&lt;BR /&gt;
UDP/514 = cisco:asa&lt;BR /&gt;
UDP/515 = cisco:ios&lt;BR /&gt;
UDP/515 = cisco:acs&lt;BR /&gt;
UDP/516 = myunixsyslogfeeds&lt;/P&gt;

&lt;P&gt;2) Alternatively, you can configure props and transforms to assign the sourcetype based on a match against the host content.&lt;/P&gt;

&lt;P&gt;See this article for more information : &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.2/Data/Advancedsourcetypeoverrides"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.2/Data/Advancedsourcetypeoverrides&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you do either of the above, then at search time you can specifcy sourcetype=cisco:asa or sourcetype=cisco:acs etc.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Mar 2015 13:44:09 GMT</pubDate>
    <dc:creator>esix_splunk</dc:creator>
    <dc:date>2015-03-19T13:44:09Z</dc:date>
    <item>
      <title>If I have multiple Cisco devices sending syslog directly to Splunk with the same source and sourcetype, how do I view them separately?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-I-have-multiple-Cisco-devices-sending-syslog-directly-to/m-p/180477#M36201</link>
      <description>&lt;P&gt;Although we have multiple threads related to this topic, none are useful and confusing for newbies like me.&lt;/P&gt;

&lt;P&gt;I have multiple Cisco devices (Routers, ASA firewall, ACS server)  and all are sending syslog info directly to Splunk.&lt;/P&gt;

&lt;P&gt;I'd really feel grateful if anybody can give step by step recommendation on how to view them separately?.&lt;/P&gt;

&lt;P&gt;I am confused especially when the sourcetype and source are showing cisco:asa for all the devices that is being searched (say for example, i m looking logs for SMTP relay and it is showing sourcetype as ASA)&lt;/P&gt;

&lt;P&gt;Please help me friends!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 11:41:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-I-have-multiple-Cisco-devices-sending-syslog-directly-to/m-p/180477#M36201</guid>
      <dc:creator>mi5cyberninja</dc:creator>
      <dc:date>2015-03-19T11:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: If I have multiple Cisco devices sending syslog directly to Splunk with the same source and sourcetype, how do I view them separately?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-I-have-multiple-Cisco-devices-sending-syslog-directly-to/m-p/180478#M36202</link>
      <description>&lt;P&gt;in search and repporting app&lt;BR /&gt;
build 3 search:&lt;BR /&gt;
1 with source=first source file  who is in your index and save it like eventype Routers&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    index=my_index source=first_source_name 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;2 &lt;CODE&gt;index=my_index source=second_source_name&lt;/CODE&gt; save it  like eventype asa_firewall&lt;BR /&gt;
3&lt;CODE&gt;index=my_index source=third_source_name&lt;/CODE&gt; save it like eventype acs_server&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:11:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-I-have-multiple-Cisco-devices-sending-syslog-directly-to/m-p/180478#M36202</guid>
      <dc:creator>tachifelix</dc:creator>
      <dc:date>2020-09-28T19:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: If I have multiple Cisco devices sending syslog directly to Splunk with the same source and sourcetype, how do I view them separately?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-I-have-multiple-Cisco-devices-sending-syslog-directly-to/m-p/180479#M36203</link>
      <description>&lt;P&gt;This is most likely because all of your devices are sending to the UDP input on the Splunk server, and you have that UDP input configured as cisco:asa. There are a few options to change this:&lt;/P&gt;

&lt;P&gt;1) Create different UDP inputs for each device type:&lt;BR /&gt;
UDP/514 = cisco:asa&lt;BR /&gt;
UDP/515 = cisco:ios&lt;BR /&gt;
UDP/515 = cisco:acs&lt;BR /&gt;
UDP/516 = myunixsyslogfeeds&lt;/P&gt;

&lt;P&gt;2) Alternatively, you can configure props and transforms to assign the sourcetype based on a match against the host content.&lt;/P&gt;

&lt;P&gt;See this article for more information : &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.2/Data/Advancedsourcetypeoverrides"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.2/Data/Advancedsourcetypeoverrides&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you do either of the above, then at search time you can specifcy sourcetype=cisco:asa or sourcetype=cisco:acs etc.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 13:44:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-I-have-multiple-Cisco-devices-sending-syslog-directly-to/m-p/180479#M36203</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2015-03-19T13:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: If I have multiple Cisco devices sending syslog directly to Splunk with the same source and sourcetype, how do I view them separately?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-I-have-multiple-Cisco-devices-sending-syslog-directly-to/m-p/180480#M36204</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/202391"&gt;@esix_splunk&lt;/a&gt; : OK, 1st option is good but still I would like to choose second option:&lt;/P&gt;

&lt;P&gt;The document says:&lt;/P&gt;

&lt;P&gt;Create a stanza in transforms.conf that follows this syntax:&lt;/P&gt;

&lt;P&gt;[] - my value here is cisco_acs &amp;amp;  SMTP&lt;BR /&gt;
REGEX =   - &lt;BR /&gt;
FORMAT = sourcetype:: - &lt;BR /&gt;
DEST_KEY = MetaData:Sourcetype&lt;/P&gt;

&lt;P&gt;Could you please decode the above stanza for  cisco acs and SMTP relay logs?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:11:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-I-have-multiple-Cisco-devices-sending-syslog-directly-to/m-p/180480#M36204</guid>
      <dc:creator>mi5cyberninja</dc:creator>
      <dc:date>2020-09-28T19:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: If I have multiple Cisco devices sending syslog directly to Splunk with the same source and sourcetype, how do I view them separately?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-I-have-multiple-Cisco-devices-sending-syslog-directly-to/m-p/180481#M36205</link>
      <description>&lt;P&gt;Or even better, install the technology addons for Cisco ASA and ACS, most of it works just fine out of the box &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
If you're using a distributed environment, install them on your forwarders.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://apps.splunk.com/app/1620/"&gt;https://apps.splunk.com/app/1620/&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://apps.splunk.com/app/1811/"&gt;https://apps.splunk.com/app/1811/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 15:54:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-I-have-multiple-Cisco-devices-sending-syslog-directly-to/m-p/180481#M36205</guid>
      <dc:creator>Sloefke</dc:creator>
      <dc:date>2015-03-19T15:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: If I have multiple Cisco devices sending syslog directly to Splunk with the same source and sourcetype, how do I vie</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-I-have-multiple-Cisco-devices-sending-syslog-directly-to/m-p/521888#M88151</link>
      <description>&lt;P&gt;You'd be better to start a new thread and ask the community for help in that manner.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, look at the Cisco IOS and ASA TA's that have all the extractions in place. You most likely can find the solution there.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 21:08:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-I-have-multiple-Cisco-devices-sending-syslog-directly-to/m-p/521888#M88151</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2020-09-28T21:08:42Z</dc:date>
    </item>
  </channel>
</rss>

