Getting Data In

how to monitor network logs

surekhasplunk
Communicator

Hi,

I have cisco, checkpoint, fortinet, arista, pulse secure etc devices which needs to be monitored for network, bandwidth, packet drops usage etc.

So what would be the best approach to achieve it. Which app i should use

Thanks

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

No one app will handle all of those devices. Look in apps.splunk.com for apps that support the products you use.

Just installing apps may not be enough. Apps will process logs, but don't always fetch the logs themselves. You probably will have to configure the devices to send their logs in syslog format to a syslog server. Then install the Splunk Universal Forwarder on the syslog server to pass the logs to Splunk. See http://www.georgestarcher.com/splunk-success-with-syslog/.

What you can monitor for depends on the data provided to Splunk by your devices. For instance, you can't look for packet drops if packet drops are not logged.

This is a very general question. Feel free to post new, specific questions as you go.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

No one app will handle all of those devices. Look in apps.splunk.com for apps that support the products you use.

Just installing apps may not be enough. Apps will process logs, but don't always fetch the logs themselves. You probably will have to configure the devices to send their logs in syslog format to a syslog server. Then install the Splunk Universal Forwarder on the syslog server to pass the logs to Splunk. See http://www.georgestarcher.com/splunk-success-with-syslog/.

What you can monitor for depends on the data provided to Splunk by your devices. For instance, you can't look for packet drops if packet drops are not logged.

This is a very general question. Feel free to post new, specific questions as you go.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...