Getting Data In

how to monitor network logs

surekhasplunk
Communicator

Hi,

I have cisco, checkpoint, fortinet, arista, pulse secure etc devices which needs to be monitored for network, bandwidth, packet drops usage etc.

So what would be the best approach to achieve it. Which app i should use

Thanks

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

No one app will handle all of those devices. Look in apps.splunk.com for apps that support the products you use.

Just installing apps may not be enough. Apps will process logs, but don't always fetch the logs themselves. You probably will have to configure the devices to send their logs in syslog format to a syslog server. Then install the Splunk Universal Forwarder on the syslog server to pass the logs to Splunk. See http://www.georgestarcher.com/splunk-success-with-syslog/.

What you can monitor for depends on the data provided to Splunk by your devices. For instance, you can't look for packet drops if packet drops are not logged.

This is a very general question. Feel free to post new, specific questions as you go.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

No one app will handle all of those devices. Look in apps.splunk.com for apps that support the products you use.

Just installing apps may not be enough. Apps will process logs, but don't always fetch the logs themselves. You probably will have to configure the devices to send their logs in syslog format to a syslog server. Then install the Splunk Universal Forwarder on the syslog server to pass the logs to Splunk. See http://www.georgestarcher.com/splunk-success-with-syslog/.

What you can monitor for depends on the data provided to Splunk by your devices. For instance, you can't look for packet drops if packet drops are not logged.

This is a very general question. Feel free to post new, specific questions as you go.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...