Splunk Enterprise

Splunk Add-on for Juniper parsing issues for Juniper SRX logs

srek3502
Explorer

 

Hi,

We are seeing log parsing issue with Juniper SRX logs for the following logs
RT_FLOW_SESSION_CREATE
RT_FLOW_SESSION_CLOSE.
It doesn't parsing at all. As far as i could see from the release notes that the Add-on has a known issues with Junper SRX Logs Parsing for RT_FLOW_SESSION_CLOSE_LS. However not with the ones which i mentioned above (RT_FLOW_SESSION_CREATE or RT_FLOW_SESSION_CLOSE).
Can you please help. Is this related. ?
Date filed Issue number Description
2022-12-29 ADDON-59372 Junper SRX Logs Parsing for RT_FLOW_SESSION_CLOSE_LS

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

As far as I remember the Add-on we got from splunkbase (but I admit, it was some 4 years ago or something like that) wouldn't parse some fields properly. We ended up fixing the transforms by hand.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...