Splunk Enterprise

RWI

z_kat
Explorer

I am new to splunk and need some guidance. I have install RWI and the add-in's required. 

I would like to pull the Active VPN Sessions and number of VPN logins  from my SonicWall firewall, but I'm not sure where to start so that I can see this information in the RWI Dashboard.  

Regards,

Z_Kat

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Are you Splunking your SonicWall data?  If not, that's the best place to start.

If you do have the data indexed then you need to modify the dashboard to search for your data instead of whatever it searches by default.

---
If this reply helps you, Karma would be appreciated.

z_kat
Explorer

I am not currently splunking that data.   I am assuming that I would just send it to splunk via syslog.  Is that a correct assumption or is there a better method? 

0 Karma

z_kat
Explorer

I've set up the firewall to send syslog data to splunk.  I've set up splunk to accept tcp:514 source type syslog and index = vpn 

I am not receiving any data. What am I missing? 

0 Karma

z_kat
Explorer

I found the syslog installation and set it up under files and directories and I can now see the syslog data coming in from the firewall wall. 

Now my question is how do I get into RWI.  the rw_vpn_indexes is set to index VPN.  I probably need to change the nodename but I'm not sure what to change it to or where to change it.

| tstats dc(All_Sessions.user) from datamodel=Network_Sessions where `rw_vpn_indexes` nodename=All_Sessions.VPN

I could also be going completely down the wrong rabbit hole. 

I've been reading the documentation but nothing has hit home yet. 

Thanks,

Z

 

0 Karma
Get Updates on the Splunk Community!

Buttercup Games Tutorial Extension - part 9

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games Tutorial Extension - part 8

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Introducing the Splunk Developer Program!

Hey Splunk community! We are excited to announce that Splunk is launching the Splunk Developer Program in ...