All Apps and Add-ons

Rubrik Splunk Add-On: Logs from cluster showing up as sourcetypes

I'm setting up the rubrik app,
and it's assuming I've got sourcetypes of rubrik (sourcetype="rubrik:eventfeed") coming in.

I do have logs coming from our rubrik cluster but they are not showing up as that.

Do I need to change something on the clusters, Splunk or edit the instructions?

Sorry, I'm a Splunk noob.

0 Karma

Esteemed Legend

You can either edit the app and change all the places that say sourcetype="rubrik:eventfeed" OR you can CLONE_SOURCETYPE in transforms.conf

0 Karma