Deployment Architecture

In Splunk Cloud, juniper logs can be extracted using props and transforms: How to do field attraction?

btsmerchstor78
New Member

We use Splunk cloud and one on-premises HF
Using Splunk_TA_juniper in Splunk cloud, we get Juniper logs as syslogs
What I need to do to do field attraction

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @btsmerchstor78,

the Juniper_TA makes transformations and sourcetype override, so you have to install the TA also on your on-premise HF that's the first full Splunk instance that your Juniper data passing through.

By default in the TA there isn't any input, so in your input you have to assign the sourcetype "juniper" to your data source, so the add-on takes these logs and makes a transformation assigning the correct sourcetypes and parsing rules.

It's important that the input you enabled is done following the instructions of the above documentation.

Ciao.

Giuseppe

 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...