Splunk Enterprise Security

Zscaler add-on field extraction

bhsakarchourasi
Path Finder

Hi All,

We receiving zscaler logs on syslog server from there forwarder is reading logs and sending to Splunk cloud.

Zscaler add on is installed on forwarder as well as on search head but the log field extraction is not as expected.

just want to know if anyone has faced such issue with zscaler add on, if yes than how to resolve it.

Thanks,
Bhaskar

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...