All Apps and Add-ons

Help with Juniper SRX App - sourcetype=srx_traffic

mpegan
New Member

I loaded the app "Splunk for Juniper SRX". I'm running Splunk 4.3. I don't seen any data being popultaed into the app.

I can see the syslog data within the native seach app. When I click on the Juniper apps I get the following error.

The following messages were returned by the search subsystem:
DEBUG: base lispy: [ AND sourcetype::srx_traffic ]
DEBUG: search context: user="mpegan", app="SplunkforJuniperSRX", bs-pathname="/opt/splunk/etc"

I'm very new to Splunk and don't know how to troubleshoot this. Do I need to configure the sourcetype srx_traffic?

Any help is greatly appreciated. Thanks

0 Karma
1 Solution

MarioM
Motivator

the sourcetype needs to be srx_log

There is a README in the apps folder SPLUNK_HOME/etc/apps/SplunkforJuniperSRX/

View solution in original post

pollo123
New Member

it seems that I cannot get any data, im using splunk port 514 for udp

0 Karma

MarioM
Motivator

the sourcetype needs to be srx_log

There is a README in the apps folder SPLUNK_HOME/etc/apps/SplunkforJuniperSRX/

mpegan
New Member

oh man!

That did it. Thanks so much. I was so looking forward to this app.

0 Karma

MarioM
Motivator

I am glad it did! Please accept my answer for those who have same issue to know this is the answer.Thanks

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...