Hi,
Currently I have few network devices sending logs via syslog to splunk and sourcetype is Cisco:ios and present we are testing on only one device please guide me, what is the search string to get alert for availability and interface utilisation (for one device and more device).