<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I get logs from network gear to a specific index? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-logs-from-network-gear-to-a-specific-index/m-p/387066#M95926</link>
    <description>&lt;P&gt;If your HF is receiving the syslog data directly, look for an inputs.conf setting for udp:514 and add an &lt;CODE&gt;index=mynetworkindex&lt;/CODE&gt; to it... ideally by running &lt;CODE&gt;splunk btool --debug inputs list udp&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;If your HF's machine has a syslog daemon running that receives the data (better practice!), look for a monitor stanza in your HF's inputs.conf that reads the logs from the syslog daemon off disk, and set the network index in there.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Nov 2018 17:10:58 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2018-11-16T17:10:58Z</dc:date>
    <item>
      <title>How do I get logs from network gear to a specific index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-logs-from-network-gear-to-a-specific-index/m-p/387065#M95925</link>
      <description>&lt;P&gt;I use Splunk on Windows.  I have several heavy forwarders that forward Windows event logs to my indexer cluster into indexes named for the subnet where the Windows boxes reside.  One such subnet has both Windows boxes and network gear.  The Windows boxes send logs on port 9997 while the network gear sends on port 514 to the Heavy Forwarder.  The logs from the Windows boxes show up in the appropriate index on the indexer cluster, but the network gear shows up in the &lt;EM&gt;Main&lt;/EM&gt; index.    &lt;/P&gt;

&lt;P&gt;How can I get the logs from the network gear to show up in the &lt;EM&gt;Network&lt;/EM&gt; index from that heavy Forwarder?  I believe that the solution lies in creations/modifications to the transforms.conf and props.conf files in splunkhome\etc\system\local folder.  I appreciate any help.  Thanks! &lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 15:33:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-logs-from-network-gear-to-a-specific-index/m-p/387065#M95925</guid>
      <dc:creator>jmads</dc:creator>
      <dc:date>2018-11-16T15:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get logs from network gear to a specific index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-logs-from-network-gear-to-a-specific-index/m-p/387066#M95926</link>
      <description>&lt;P&gt;If your HF is receiving the syslog data directly, look for an inputs.conf setting for udp:514 and add an &lt;CODE&gt;index=mynetworkindex&lt;/CODE&gt; to it... ideally by running &lt;CODE&gt;splunk btool --debug inputs list udp&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;If your HF's machine has a syslog daemon running that receives the data (better practice!), look for a monitor stanza in your HF's inputs.conf that reads the logs from the syslog daemon off disk, and set the network index in there.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 17:10:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-logs-from-network-gear-to-a-specific-index/m-p/387066#M95926</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2018-11-16T17:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get logs from network gear to a specific index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-logs-from-network-gear-to-a-specific-index/m-p/387067#M95927</link>
      <description>&lt;P&gt;Thanks, Martin!  I have to unexpectedly leave work early today, but will give this a shot first thing Monday morning!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 18:25:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-logs-from-network-gear-to-a-specific-index/m-p/387067#M95927</guid>
      <dc:creator>jmads</dc:creator>
      <dc:date>2018-11-16T18:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get logs from network gear to a specific index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-logs-from-network-gear-to-a-specific-index/m-p/387068#M95928</link>
      <description>&lt;P&gt;Martin, this worked like a champ!  Thanks for the help!&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2018 11:52:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-get-logs-from-network-gear-to-a-specific-index/m-p/387068#M95928</guid>
      <dc:creator>jmads</dc:creator>
      <dc:date>2018-11-20T11:52:19Z</dc:date>
    </item>
  </channel>
</rss>

