<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best way to get JunOS logs into Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-JunOS-logs-into-Splunk/m-p/12575#M96476</link>
    <description>&lt;P&gt;I believe most of the Juniper firewalls are capable of sending syslog type output and they also write to log files.  I know of multiple use cases where Juniper data is sent via a network input to Splunk.  I see two options:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Leverage the log forwarding capability of the firewall and send it to Splunk via a network input (typically port 514 UDP or TCP, and make sure you specify syslog sourcetype)&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;If you can send the file to a directory on the Splunk system, you could use a basic file or directory monitoring input.  You would also want to specify the syslog sourcetype in this configuration.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;For more information on creating inputs:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/WhatSplunkcanmonitor" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Admin/WhatSplunkcanmonitor&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Apr 2010 23:40:55 GMT</pubDate>
    <dc:creator>Simeon</dc:creator>
    <dc:date>2010-04-29T23:40:55Z</dc:date>
    <item>
      <title>Best way to get JunOS logs into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-JunOS-logs-into-Splunk/m-p/12574#M96475</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am new to Splunk and I am trying to workout the best way to get logs from JunOS based firewalls into Splunk. I am currently using Syslogh, but this isn't getting all the information I am after. Could someone advise the most reliable way of collecting the informaiton?&lt;/P&gt;

&lt;P&gt;I am trying to get the logs from Juniper SRX firewalls.&lt;/P&gt;

&lt;P&gt;I would also like to know how I could achieve change monitoring as well?&lt;/P&gt;

&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2010 23:07:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-JunOS-logs-into-Splunk/m-p/12574#M96475</guid>
      <dc:creator>craigallen</dc:creator>
      <dc:date>2010-04-29T23:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to get JunOS logs into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-JunOS-logs-into-Splunk/m-p/12575#M96476</link>
      <description>&lt;P&gt;I believe most of the Juniper firewalls are capable of sending syslog type output and they also write to log files.  I know of multiple use cases where Juniper data is sent via a network input to Splunk.  I see two options:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;Leverage the log forwarding capability of the firewall and send it to Splunk via a network input (typically port 514 UDP or TCP, and make sure you specify syslog sourcetype)&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;If you can send the file to a directory on the Splunk system, you could use a basic file or directory monitoring input.  You would also want to specify the syslog sourcetype in this configuration.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;For more information on creating inputs:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/WhatSplunkcanmonitor" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Admin/WhatSplunkcanmonitor&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2010 23:40:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-JunOS-logs-into-Splunk/m-p/12575#M96476</guid>
      <dc:creator>Simeon</dc:creator>
      <dc:date>2010-04-29T23:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to get JunOS logs into Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-JunOS-logs-into-Splunk/m-p/12576#M96477</link>
      <description>&lt;P&gt;i am using juniper ISG 2000, i am looking for splunk app, which can monitor my juniper logs. I tried severals apps for juniper, but i got nothing.&lt;BR /&gt;
My juniper runs on junos.&lt;/P&gt;

&lt;P&gt;Could you give me the requisite app, and the documentation ??&lt;/P&gt;

&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2014 09:36:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-way-to-get-JunOS-logs-into-Splunk/m-p/12576#M96477</guid>
      <dc:creator>jeandez</dc:creator>
      <dc:date>2014-03-13T09:36:32Z</dc:date>
    </item>
  </channel>
</rss>

