Getting Data In

Where is the option to set the data source for apps?

skoszegi
New Member

Hi All,

My scenario: I receive log files from a customer which I need to analyze and build reports from it. I was able to import the data into Spunk, but it can't seem to work with any app I tried. I couldn't find the option to set data source for apps, are they only working with "forwarded" data?

Thanks,
Szabolcs

Tags (2)
0 Karma

gyslainlatsa
Motivator

for your apps Splunk App for Checkpoint, Cisco Networks, following this link for the best configurations
http://docs.splunk.com/Documentation/OPSEC-LEA/2.1.1/Install/InstalltheSplunkTechnologyAdd-onforChec...

0 Karma

btt
Path Finder

In data summary page (page show by gyslainlatsa), select Sources
and in the displayed list click on your source to see if you have events

0 Karma

skoszegi
New Member

Yes I have events there and I'm they are visible in the Searching & reporting app but not in other apps.

0 Karma

gyslainlatsa
Motivator

hi skoszegi,

click on the application search and reporting
click on summary data and verified sources and sourcetype presents in your splunk machine to see if the source are not displayed.
here's a figure to help.
let me know for the future.
please forgive my english.alt text

0 Karma

skoszegi
New Member

Splunk App for Checkpoint, Cisco Networks

0 Karma

aweitzman
Motivator

Many apps require that the data needs to flow through a particular add-on into Splunk. For instance, the blurb for the CheckPoint app indicates that it requires the data to be "collected using the Splunk Add-on for Check Point OPSEC LEA" for it to work. There are many Cisco apps, so I'm not sure which one you're using, but it may have similar requirements.

0 Karma

skoszegi
New Member

Oh that could be an issue! Will install the add-on and see if it works.

Thanks

0 Karma

skoszegi
New Member

Hi,

Thanks for your answer. I already checked it and I can see it in the sources and search. But if I open for example the Cisco app, it shows no data but there are Cisco logs in these sources.

0 Karma

gyslainlatsa
Motivator

your work with what apps?

0 Karma
Get Updates on the Splunk Community!

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more with ITSI’s ...

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more! Faster Time to ValueManaging and ...

New Release | Splunk Enterprise 9.3

Admins and Analyst can benefit from:  Seamlessly route data to your local file system to save on storage ...

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...