I am new at splunk.i have got a task to do and its like kind of monitoring home network security and for that i have to send the router data to splunk for analysis.
any suggestions about how to do this?
Thanks in advance.
Hi @ShihabOmar ,
You can follow below two options to forward router data to Splunk.
1) Router - > syslog(with the help of splunk agent) -> Splunk indexers
2) Router -> Heavy forwarder(Enable the port for listening) ->Splunk indexer.
Appreciate your help.
Is there any documentation about how to get the syslog from router and how to send it to splunk?
thanks
This really depends on your router manufacturer. You could easily google something like: Linksys LRT224 syslog configuration (https://community.linksys.com/t5/Linksys-Small-Business/Syslog-setting-for-LRT224/td-p/1346325) so pointing your router to your syslog server (Or splunk directly if it is the only syslog device and you enabled the port on your splunk server) should get you what you need.
http://www.network-node.com/blog/2017/7/2/cisco-networks-splunk-app
@ShihabOmar Check if this works for you?
Also check this docs page: https://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports