All Apps and Add-ons

srx_log srx_traffic

anywhere99
Explorer

Hi I have a problem with the transform.conf, the logs are not parse from the log source srx_log - to be slit up to eventtype= srx_traffic and srx_threat.

So the app dashboard and so on does not show any data, but the logs are coming in as srx_log
Any suggestions?

Tags (1)
0 Karma

anywhere99
Explorer

Solved, set the traffic log in the srx to structured data.
Thanks Splunk support for the auto combination 😃

0 Karma
Get Updates on the Splunk Community!

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Customers Increasingly Choose Splunk for Observability

For the second year in a row, Splunk was recognized as a Leader in the 2024 Gartner® Magic Quadrant™ for ...

Bridging the Gap: Splunk Helps Students Move from Classroom to Career

The Splunk Community is a powerful network of users, educators, and organizations working together to tackle ...