Getting Data In

How to feed syslog of another Cisco device to Splunk?


There are two Cisco devices; I call them “1st IP” and “2nd IP” hereafter.

I have managed to configured and send syslog of “1st IP” to Splunk. Please see following 2 screenshots.
alt text

Now i would like to another Cisco device, i.e. “2nd IP” to Splunk, by adding the “2nd IP”. It turned out to be weird to me.

All i wanted is something like this by always using soucetype:cisco, if possible:
UDP port---------------------souce type
192.168.1stIP:514-------- cisco

alt text

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...