we migrated from netiq to Splunk recently, we wanted to have a same report here also such as Cisco, juniper device change.
so do i need to create any lookup or data model ?
is there any query already written for this, please help me to write the query do suggest best way to do this.
we haven't started to ingest logs of Cisco into Splunk.
do we have to have any preconfigured sourectype or splunk automatically takes the sourcetype.