All Apps and Add-ons

Sending Cisco Umbrella data to syslog server

mpuchalski
Loves-to-Learn

Anyone know how to configure the Cisco Umbrella Add-on to also send the Umbrella logs to a syslog server? 

I've tried the info here (https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd#Sysl...) but I seem to get all data coming into my splunk system, not just the Umbrella logs.

I'm wondering if there's a way to make it work for only the Umbrella data.

Thanks!

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...