I am new to Splunk but spent a log time with Unifi kit. I am on the latest version of Unifi controller with a config for SIEM integration with Splunk. I have installed Splunk on a Proxmox VM using Ubuntu 24.04.
Is there a step-by-step guid on how to ingest my syslog data from Unifi into Splunk please?
Regards,
BOOMEL
Don't ingest syslog directly into Splunk. Use a dedicated syslog server. See https://www.splunk.com/en_us/blog/tips-and-tricks/using-syslog-ng-with-splunk.html and https://kinneygroup.com/blog/splunk-syslog/