All Apps and Add-ons

srx_log srx_traffic

anywhere99
Explorer

Hi I have a problem with the transform.conf, the logs are not parse from the log source srx_log - to be slit up to eventtype= srx_traffic and srx_threat.

So the app dashboard and so on does not show any data, but the logs are coming in as srx_log
Any suggestions?

Tags (1)
0 Karma

anywhere99
Explorer

Solved, set the traffic log in the srx to structured data.
Thanks Splunk support for the auto combination 😃

0 Karma
Get Updates on the Splunk Community!

Bridging the Gap: Splunk Helps Students Move from Classroom to Career

The Splunk Community is a powerful network of users, educators, and organizations working together to tackle ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...