Splunk Enterprise

Splunk Add-on for Juniper parsing issues for Juniper SRX logs

srek3502
Explorer

 

Hi,

We are seeing log parsing issue with Juniper SRX logs for the following logs
RT_FLOW_SESSION_CREATE
RT_FLOW_SESSION_CLOSE.
It doesn't parsing at all. As far as i could see from the release notes that the Add-on has a known issues with Junper SRX Logs Parsing for RT_FLOW_SESSION_CLOSE_LS. However not with the ones which i mentioned above (RT_FLOW_SESSION_CREATE or RT_FLOW_SESSION_CLOSE).
Can you please help. Is this related. ?
Date filed Issue number Description
2022-12-29 ADDON-59372 Junper SRX Logs Parsing for RT_FLOW_SESSION_CLOSE_LS

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

As far as I remember the Add-on we got from splunkbase (but I admit, it was some 4 years ago or something like that) wouldn't parse some fields properly. We ended up fixing the transforms by hand.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...