<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAS logs integrating to Splunk in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696862#M10341</link>
    <description>&lt;P&gt;Yes, i need configuration rsyslog or syslog-ng on the Linux server&lt;/P&gt;</description>
    <pubDate>Tue, 20 Aug 2024 15:16:40 GMT</pubDate>
    <dc:creator>vid1</dc:creator>
    <dc:date>2024-08-20T15:16:40Z</dc:date>
    <item>
      <title>NAS logs integrating to Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696852#M10335</link>
      <description>&lt;P&gt;we need a NAS logs integration to splunk but i dont know how to integrate .We have SC4s container. can anyone help on this&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 14:19:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696852#M10335</guid>
      <dc:creator>vid1</dc:creator>
      <dc:date>2024-08-20T14:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: NAS logs integrating to Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696855#M10336</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/270977"&gt;@vid1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what's your NAS technology? is there ad Add-On for it in apps.splunk.com?&lt;/P&gt;&lt;P&gt;if yes, install it on the Forwarder and on the Search Head.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 14:41:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696855#M10336</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-08-20T14:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: NAS logs integrating to Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696856#M10337</link>
      <description>&lt;P&gt;NAS (powerscale storage logs)&amp;nbsp; we&amp;nbsp; need syslog configuration in HF .how to config syslog in our hf&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 14:52:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696856#M10337</guid>
      <dc:creator>vid1</dc:creator>
      <dc:date>2024-08-20T14:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: NAS logs integrating to Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696857#M10338</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/270977"&gt;@vid1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;check if the Dell PowerScale Add-On for Splunk (&lt;A href="https://splunkbase.splunk.com/app/2689" target="_blank"&gt;https://splunkbase.splunk.com/app/2689&lt;/A&gt;) is the correct one for you.&lt;/P&gt;&lt;P&gt;Otherwise you have to create your own custom add-on.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 14:58:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696857#M10338</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-08-20T14:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: NAS logs integrating to Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696859#M10339</link>
      <description>&lt;P&gt;that add on as not working .we can logs collect from syslog server&amp;nbsp; but i don't know how to configure&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 15:00:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696859#M10339</guid>
      <dc:creator>vid1</dc:creator>
      <dc:date>2024-08-20T15:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: NAS logs integrating to Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696861#M10340</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/270977"&gt;@vid1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;are you speaking of output configuration on NAS or syslog input Configuration on SC4S?&lt;/P&gt;&lt;P&gt;About NAS, I cannot help you, you should search in the NAS Management menu.&lt;/P&gt;&lt;P&gt;About SC4S, I don't like it, I prefer to configure rsyslog (or syslog-ng) for receiving and then inputs on UF.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 15:14:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696861#M10340</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-08-20T15:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: NAS logs integrating to Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696862#M10341</link>
      <description>&lt;P&gt;Yes, i need configuration rsyslog or syslog-ng on the Linux server&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 15:16:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696862#M10341</guid>
      <dc:creator>vid1</dc:creator>
      <dc:date>2024-08-20T15:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: NAS logs integrating to Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696865#M10342</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/270977"&gt;@vid1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you have to configure three items in /etc/rsyslog.conf:&lt;/P&gt;&lt;P&gt;in the MODULES section:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;module(load="imudp") # needs to be done just once&lt;/LI-CODE&gt;&lt;P&gt;or&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;module(load="imtcp") # needs to be done just once&lt;/LI-CODE&gt;&lt;P&gt;depending on the protocol you're using.&lt;/P&gt;&lt;P&gt;then, in TEMPLATES&amp;nbsp; section:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;template(name="tmpl-paloalto" type="string" string="/var/log/remote/%fromhost%/paloalto/%HOSTNAME%/paloalto_%$YEAR%-%$MONTH%-%$DAY%_%$HOUR%.log")&lt;/LI-CODE&gt;&lt;P&gt;this string must be modified based on the path and the name of the files that must be written.&lt;/P&gt;&lt;P&gt;At least the rule to implement:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ruleset(name="writeRemoteData" queue.type="fixedArray" queue.size="250000" queue.dequeueBatchSize="4096" queue.workerThreads="4" queue.workerThreadMinimumMessages="60000")
{
  # network - paloalto
  if $HOSTNAME == "10.10.10.10" then {
    action(type="omfile" ioBufferSize="64k" flushOnTXEnd="off" asyncWriting="on" dynafile="tmpl-paloalto" DirCreateMode="0770" FileCreateMode="0660" template="fmt_default") stop
  }&lt;/LI-CODE&gt;&lt;P&gt;this is the most important and difficoult part to implement, because you have to implement all your rules.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 15:27:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/NAS-logs-integrating-to-Splunk/m-p/696865#M10342</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-08-20T15:27:49Z</dc:date>
    </item>
  </channel>
</rss>

