Hello Splunkers!
We have deployed SC4S and it works fine for Trend but we're now using it for VPN (Aviatrix) which doesn't have a prebuilt source.
Data coming into main on the fallback so we're good to go, but looking for details on HOW to add custom sources. I've been through https://splunk-connect-for-syslog.readthedocs.io/en/master/ many times but nothing really explains it.
We've deployed Bring Your Own Environment and everything is under /etc/syslog-ng.
Would really appreciate some steps on how to add new source!
Thanks