All Apps and Add-ons

Different sourcetypes for Juniper add-on and Juniper app

vsingla1
Communicator

I have installed Juniper add-on (http://docs.splunk.com/Documentation/AddOns/latest/Juniper/Sourcetypes).
Also, I will like to take advantage of the Juniper app for splunk.
BUT the app and the add-on have different sourcetypes.
The juniper app is configured to search (saved searches) on sourcetype=JuniperFW. Whereas the Juniper add-on does not have any such sourcetype (for complete list, click above link).
Can the app and Add-on be synched together? Cisco ios add-on and Cisco app does not have any such problem.

0 Karma

muebel
SplunkTrust
SplunkTrust

Yup, you can override any sourcetypes you like by created a local config file and setting the input stanza with sourcetype = .

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...