I have the Juniper device sending to syslog-NG and I am reading the file as a monitored input to splunk.
I created a PROPS.conf like below in the local directory in the Juniper SA app:
### Transform Juniper SA Log SourceType
Do I need to create a transforms.conf in the local directory?
do I need to escape the "/" like this "//"