Getting Data In

how to monitor network logs

surekhasplunk
Communicator

Hi,

I have cisco, checkpoint, fortinet, arista, pulse secure etc devices which needs to be monitored for network, bandwidth, packet drops usage etc.

So what would be the best approach to achieve it. Which app i should use

Thanks

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

No one app will handle all of those devices. Look in apps.splunk.com for apps that support the products you use.

Just installing apps may not be enough. Apps will process logs, but don't always fetch the logs themselves. You probably will have to configure the devices to send their logs in syslog format to a syslog server. Then install the Splunk Universal Forwarder on the syslog server to pass the logs to Splunk. See http://www.georgestarcher.com/splunk-success-with-syslog/.

What you can monitor for depends on the data provided to Splunk by your devices. For instance, you can't look for packet drops if packet drops are not logged.

This is a very general question. Feel free to post new, specific questions as you go.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

No one app will handle all of those devices. Look in apps.splunk.com for apps that support the products you use.

Just installing apps may not be enough. Apps will process logs, but don't always fetch the logs themselves. You probably will have to configure the devices to send their logs in syslog format to a syslog server. Then install the Splunk Universal Forwarder on the syslog server to pass the logs to Splunk. See http://www.georgestarcher.com/splunk-success-with-syslog/.

What you can monitor for depends on the data provided to Splunk by your devices. For instance, you can't look for packet drops if packet drops are not logged.

This is a very general question. Feel free to post new, specific questions as you go.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...