Getting Data In

Where is the option to set the data source for apps?

skoszegi
New Member

Hi All,

My scenario: I receive log files from a customer which I need to analyze and build reports from it. I was able to import the data into Spunk, but it can't seem to work with any app I tried. I couldn't find the option to set data source for apps, are they only working with "forwarded" data?

Thanks,
Szabolcs

Tags (2)
0 Karma

gyslainlatsa
Motivator

for your apps Splunk App for Checkpoint, Cisco Networks, following this link for the best configurations
http://docs.splunk.com/Documentation/OPSEC-LEA/2.1.1/Install/InstalltheSplunkTechnologyAdd-onforChec...

0 Karma

btt
Path Finder

In data summary page (page show by gyslainlatsa), select Sources
and in the displayed list click on your source to see if you have events

0 Karma

skoszegi
New Member

Yes I have events there and I'm they are visible in the Searching & reporting app but not in other apps.

0 Karma

gyslainlatsa
Motivator

hi skoszegi,

click on the application search and reporting
click on summary data and verified sources and sourcetype presents in your splunk machine to see if the source are not displayed.
here's a figure to help.
let me know for the future.
please forgive my english.alt text

0 Karma

skoszegi
New Member

Splunk App for Checkpoint, Cisco Networks

0 Karma

aweitzman
Motivator

Many apps require that the data needs to flow through a particular add-on into Splunk. For instance, the blurb for the CheckPoint app indicates that it requires the data to be "collected using the Splunk Add-on for Check Point OPSEC LEA" for it to work. There are many Cisco apps, so I'm not sure which one you're using, but it may have similar requirements.

0 Karma

skoszegi
New Member

Oh that could be an issue! Will install the add-on and see if it works.

Thanks

0 Karma

skoszegi
New Member

Hi,

Thanks for your answer. I already checked it and I can see it in the sources and search. But if I open for example the Cisco app, it shows no data but there are Cisco logs in these sources.

0 Karma

gyslainlatsa
Motivator

your work with what apps?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...