Splunk Cloud Platform

How to get parsed PFsense logs into Splunk Cloud instance?

shubhamk
Explorer

Hi

I am new to Splunk Cloud.
We're collecting some pfSense logs to a dedicated Syslog server and Splunk cloud is receiving those logs but they are not parsed properly. I have read a couple of articles but nothing specific to Splunk cloud.
Any ideas on how they can be parsed on Splunk cloud?

Labels (2)
Tags (3)
0 Karma
1 Solution

General_Talos
Path Finder

Can you check if your sourcetype in inputs matching with defined add-on input and same with add-on props & transform conf.

You can install add-on on Splunk HF and perform the changes (because Splunk cloud doesn't gives you feasibility to perform for any changes in installed app on cloud infra, however you can achieve this changes via on-prem HF).

 

View solution in original post

shubhamk
Explorer

Yes.. we have installed TA-pfsense on Search Heads and Indexers.

0 Karma

ryg
New Member

How did you install TA-pfsense on the Search heads? 

0 Karma

General_Talos
Path Finder

Can you check if your sourcetype in inputs matching with defined add-on input and same with add-on props & transform conf.

You can install add-on on Splunk HF and perform the changes (because Splunk cloud doesn't gives you feasibility to perform for any changes in installed app on cloud infra, however you can achieve this changes via on-prem HF).

 

shubhamk
Explorer

Thanks I had similar thoughts  but wasn't sure about it.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There are two apps for PFsense in Splunkbase.  Have you tried either one?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...