All Apps and Add-ons

Rubrik Splunk Add-On: Logs from cluster showing up as sourcetypes

I'm setting up the rubrik app,
(https://github.com/rubrikinc/rubrik-addon-for-splunk/blob/master/docs/quick-start.md)
and it's assuming I've got sourcetypes of rubrik (sourcetype="rubrik:eventfeed") coming in.

I do have logs coming from our rubrik cluster but they are not showing up as that.

Do I need to change something on the clusters, Splunk or edit the instructions?

Sorry, I'm a Splunk noob.

0 Karma

Esteemed Legend

You can either edit the app and change all the places that say sourcetype="rubrik:eventfeed" OR you can CLONE_SOURCETYPE in transforms.conf

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!