All Apps and Add-ons

Help with Juniper SRX App - sourcetype=srx_traffic

mpegan
New Member

I loaded the app "Splunk for Juniper SRX". I'm running Splunk 4.3. I don't seen any data being popultaed into the app.

I can see the syslog data within the native seach app. When I click on the Juniper apps I get the following error.

The following messages were returned by the search subsystem:
DEBUG: base lispy: [ AND sourcetype::srx_traffic ]
DEBUG: search context: user="mpegan", app="SplunkforJuniperSRX", bs-pathname="/opt/splunk/etc"

I'm very new to Splunk and don't know how to troubleshoot this. Do I need to configure the sourcetype srx_traffic?

Any help is greatly appreciated. Thanks

0 Karma
1 Solution

MarioM
Motivator

the sourcetype needs to be srx_log

There is a README in the apps folder SPLUNK_HOME/etc/apps/SplunkforJuniperSRX/

View solution in original post

pollo123
New Member

it seems that I cannot get any data, im using splunk port 514 for udp

0 Karma

MarioM
Motivator

the sourcetype needs to be srx_log

There is a README in the apps folder SPLUNK_HOME/etc/apps/SplunkforJuniperSRX/

mpegan
New Member

oh man!

That did it. Thanks so much. I was so looking forward to this app.

0 Karma

MarioM
Motivator

I am glad it did! Please accept my answer for those who have same issue to know this is the answer.Thanks

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...