Getting Data In

How to feed syslog of another Cisco device to Splunk?

splunkbeginner
Engager

There are two Cisco devices; I call them “1st IP” and “2nd IP” hereafter.

I have managed to configured and send syslog of “1st IP” to Splunk. Please see following 2 screenshots.
alt text

Now i would like to another Cisco device, i.e. “2nd IP” to Splunk, by adding the “2nd IP”. It turned out to be weird to me.

All i wanted is something like this by always using soucetype:cisco, if possible:
UDP port---------------------souce type
192.168.1stIP:514-------- cisco
192.168.2ndIP:514--------cisco

alt text

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Cultivate Your Career Growth with Fresh Splunk Training

Growth doesn’t just happen—it’s nurtured. Like tending a garden, developing your Splunk skills takes the right ...

Introducing a Smarter Way to Discover Apps on Splunkbase

We’re excited to announce the launch of a foundational enhancement to Splunkbase: App Tiering.  Because we’ve ...

How to Send Splunk Observability Alerts to Webex teams in Minutes

As a Developer Evangelist at Splunk, my team and I are constantly tinkering with technology to explore its ...