- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How do I send Cisco HSL format logs to Splunk Cloud?
arc
Loves-to-Learn
12-01-2023
11:55 PM
I am trying to send Cisco SD-WAN router logs to Splunk Cloud. I have installed Universal forwarder on the log server running syslog-ng and am able to forward text-based logs. However, the FW logs are output in HSL, and it's in netflow ver.9 format.
How can I get this type of data in Splunk Cloud ?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PickleRick

SplunkTrust
12-02-2023
12:43 AM
Netflow is for flow reporting. You need Splunk Stream
https://docs.splunk.com/Documentation/StreamApp/latest/DeployStreamApp/AboutSplunkStream
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
arc
Loves-to-Learn
12-05-2023
02:07 AM
Thanks for the advice.
My Splunk Cloud trial account has expired, so I will try it when I get a chance.
