Getting Data In

Splunk SC4S and barracuda

njusticesnb
Engager

Hello,

I am new to Splunk.  I have successfully got our SC4S server setup and sending info to Splunk.  I am working on getting data in from our Barracuda Web Filter.  The data is going in but getting assigned a source type of nix:syslog.  I have installed the BarracudaWebFilter app in Splunk but for it to work I am reading the sourcetype needs to be "barracuda".   I believe I need to add a line in the splunk_metadata.csv file on the SC4S server but not sure what it should be.  Anybody else set this up and have any info the could provide.

Thanks,

Labels (1)
0 Karma

abk_hexion
Loves-to-Learn

Hi @njusticesnb if you can help with the steps for setting up the sc4s server for getting syslog data into Splunk it will be really helpful 

0 Karma

blbr123
Path Finder

Hi can you help with the steps for setting up the sc4s server for getting syslog data into Splunk , I have gone through the document but it's quite confusing.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...