All Apps and Add-ons

Event sourcetyping

_smp_
Builder

Hi, thanks very much for this app. Can you confirm if this event from a Nexus 7K be sourcetyped to cisco:ios?

May 27 15:08:26 mydevice.mydomain.com : 2016 May 27 20:18:35.777 UTC: May 27 20:18:35 %KERN-6-SYSTEM_MSG: [36173794.518668] sd 1:0:0:0: [sdc] ASC=0x0 ASCQ=0x0 - kernel

0 Karma

woodcock
Esteemed Legend

You have to pre-configure your events such that they are sourcetyped to match what the app expects. The app takes it from there.

0 Karma

_smp_
Builder

Thanks for your reply, but I'm not sure I understand what you are suggesting I do. The event comes in with a sourcetype of syslog, which is what I thought the requirement was. Can you advise on what additional config I need to do?

0 Karma

woodcock
Esteemed Legend

There is an inputs.conf file that causes the events to be forwarded in. Inside of that, there should be a line that starts with sourctype=. It should have the following value

sourctype=cisco:ios
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...