Getting Data In

how to monitor network logs

surekhasplunk
Communicator

Hi,

I have cisco, checkpoint, fortinet, arista, pulse secure etc devices which needs to be monitored for network, bandwidth, packet drops usage etc.

So what would be the best approach to achieve it. Which app i should use

Thanks

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

No one app will handle all of those devices. Look in apps.splunk.com for apps that support the products you use.

Just installing apps may not be enough. Apps will process logs, but don't always fetch the logs themselves. You probably will have to configure the devices to send their logs in syslog format to a syslog server. Then install the Splunk Universal Forwarder on the syslog server to pass the logs to Splunk. See http://www.georgestarcher.com/splunk-success-with-syslog/.

What you can monitor for depends on the data provided to Splunk by your devices. For instance, you can't look for packet drops if packet drops are not logged.

This is a very general question. Feel free to post new, specific questions as you go.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

No one app will handle all of those devices. Look in apps.splunk.com for apps that support the products you use.

Just installing apps may not be enough. Apps will process logs, but don't always fetch the logs themselves. You probably will have to configure the devices to send their logs in syslog format to a syslog server. Then install the Splunk Universal Forwarder on the syslog server to pass the logs to Splunk. See http://www.georgestarcher.com/splunk-success-with-syslog/.

What you can monitor for depends on the data provided to Splunk by your devices. For instance, you can't look for packet drops if packet drops are not logged.

This is a very general question. Feel free to post new, specific questions as you go.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...