<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Field extraction via props/transforms for juniper logs in splunk cloud in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630930#M9249</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that you already configured the input from Juniper.&lt;/P&gt;&lt;P&gt;If not, follow the instructions at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/AddOns/latest/juniper/About?_ga=2.107177089.2041590115.1672646338-1358809174.1667771201&amp;amp;_gl=1*jhzgs1*_ga*MTM1ODgwOTE3NC4xNjY3NzcxMjAx*_ga_5EPM2P39FV*MTY3NjQ1MTg0MS41MDEuMS4xNjc2NDUzMzIxLjU0LjAuMA." target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/latest/juniper/About?_ga=2.107177089.2041590115.1672646338-1358809174.1667771201&amp;amp;_gl=1*jhzgs1*_ga*MTM1ODgwOTE3NC4xNjY3NzcxMjAx*_ga_5EPM2P39FV*MTY3NjQ1MTg0MS41MDEuMS4xNjc2NDUzMzIxLjU0LjAuMA.&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 15 Feb 2023 09:29:13 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-02-15T09:29:13Z</dc:date>
    <item>
      <title>Field extraction via props/transforms for juniper logs in splunk cloud?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630926#M9246</link>
      <description>&lt;P&gt;hai team,&lt;/P&gt;
&lt;P&gt;we are using splunk cloud and one prem HF&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we are getting juniper logs as syslogs and we are using &lt;SPAN&gt;Splunk_TA_juniper in splunk cloud&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;how to do field attraction from my end&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 15:39:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630926#M9246</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-02-15T15:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction via props/transforms for juniper logs in splunk cloud</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630927#M9247</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if syslogs from Juniper arrive to Splunk Cloud passing through one or more HFs, you have to install the&amp;nbsp;&lt;SPAN&gt;Splunk_TA_juniper also on the HFs because data are coocked on the first Full Splunk instance (HFs) where they are passing trough.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 09:22:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630927#M9247</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-15T09:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction via props/transforms for juniper logs in splunk cloud</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630929#M9248</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;once installed any config need to do ? will it automatically take&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 09:27:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630929#M9248</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-02-15T09:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction via props/transforms for juniper logs in splunk cloud</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630930#M9249</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that you already configured the input from Juniper.&lt;/P&gt;&lt;P&gt;If not, follow the instructions at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/AddOns/latest/juniper/About?_ga=2.107177089.2041590115.1672646338-1358809174.1667771201&amp;amp;_gl=1*jhzgs1*_ga*MTM1ODgwOTE3NC4xNjY3NzcxMjAx*_ga_5EPM2P39FV*MTY3NjQ1MTg0MS41MDEuMS4xNjc2NDUzMzIxLjU0LjAuMA." target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/latest/juniper/About?_ga=2.107177089.2041590115.1672646338-1358809174.1667771201&amp;amp;_gl=1*jhzgs1*_ga*MTM1ODgwOTE3NC4xNjY3NzcxMjAx*_ga_5EPM2P39FV*MTY3NjQ1MTg0MS41MDEuMS4xNjc2NDUzMzIxLjU0LjAuMA.&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 09:29:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630930#M9249</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-15T09:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction via props/transforms for juniper logs in splunk cloud</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630934#M9250</link>
      <description>&lt;P&gt;we already configured the inputs for syslogs&amp;nbsp;&lt;/P&gt;&lt;P&gt;but if we configured again for the input using ADDON is it leads duplicate logs&amp;nbsp;&lt;/P&gt;&lt;P&gt;and if we install TA in HF what is the config we need to do for extraction&amp;nbsp;&lt;/P&gt;&lt;P&gt;does it required inputs or props&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 09:55:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630934#M9250</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-02-15T09:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction via props/transforms for juniper logs in splunk cloud</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630936#M9251</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that you are ingesting logs from Juniper using an HF.&lt;/P&gt;&lt;P&gt;Is the HF where you enabled inputs the same that sends logs to Splunk Cloud or there's another intermediate HF?&lt;/P&gt;&lt;P&gt;On the first HF you have to use the Splunk_TA_for_Juniper enabling the wanted inputs, don't use another app or inputs outside the add-on.&lt;/P&gt;&lt;P&gt;In this way you correctly ingest logs, that are correctly parsed by the add-on and sent to Splunk Splunk.&lt;/P&gt;&lt;P&gt;On Splunk Cloud you have to install the same TA for the search time configurations.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 10:07:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630936#M9251</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-15T10:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction via props/transforms for juniper logs in splunk cloud</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630938#M9252</link>
      <description>&lt;P&gt;To be precise, the data is _parsed_ on the HFs, not cooked. Data is cooked on UFs and sent cooked to HFs/indexers. It is parsed on HF and sent to indexers (hence the advice to avoid using HF unless absolutely needed - parsed data is much bigger in volume than cooked data).&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 10:37:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630938#M9252</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-02-15T10:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction via props/transforms for juniper logs in splunk cloud</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630940#M9260</link>
      <description>&lt;P&gt;yes we have multiple HF "s getting syslogs to splunk cloud for juniper.&lt;/P&gt;&lt;P&gt;so how we can install ADDON and we need to disable syslog inputs&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 10:59:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630940#M9260</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-02-15T10:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction via props/transforms for juniper logs in splunk cloud</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630941#M9261</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you don't need to disable all syslogs, only the ones from Juniper,&lt;/P&gt;&lt;P&gt;at the same time the Splunk_TA_Juniper must be installed only in HFs used to ingest logs from Juniper not in all HFs.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 11:11:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630941#M9261</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-15T11:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction via props/transforms for juniper logs in splunk cloud</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630949#M9262</link>
      <description>&lt;P&gt;okay so we can disable syslog input and once installed need to create new inputs in&amp;nbsp; TA ADDON right&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 12:12:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630949#M9262</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-02-15T12:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction via props/transforms for juniper logs in splunk cloud</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630952#M9263</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;remember to use the sourcetype=juniper in you udp input.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 13:01:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630952#M9263</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-15T13:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction via props/transforms for juniper logs in splunk cloud</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630954#M9264</link>
      <description>&lt;P&gt;where is it while doing inputs.conf file or in the device end while configuring to send syslogs&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 13:13:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630954#M9264</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-02-15T13:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Field extraction via props/transforms for juniper logs in splunk cloud</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630956#M9265</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sourcetype is defined by GUI or by inputs.conf file.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 13:30:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Field-extraction-via-props-transforms-for-juniper-logs-in-splunk/m-p/630956#M9265</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-15T13:30:08Z</dc:date>
    </item>
  </channel>
</rss>

