Getting Data In

KiwiSyslog with Splunk

sherrysafdar
Explorer

I have a syslog server and all the syslogs are currently going to KiwiSyslog. I have the Splunk Enterprise addition and would like to get data from KiwiSyslog server. I have already installed Splunk Universal Forwarder and I can see the data in the Splunk.

The question is how can I change the sourcetype or sourcename and call it instead of source="F:\Syslog\Cisco\Switches\xyz.log to something like _sourcetype="CISCO_SWITCHES"

Please advise!

Thanks,

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...