Splunk Enterprise

seperating arcsightlogs in heavyforwarder

Path Finder

I decided to send some juniper and fortigate logs to an arcsight smart connector and then send its output to splunk heavy forwarder and then route them to different indexera based on their source( srx or fortigate) , is it possible when all the logs come from one arcsight host? whats the solution?

Tags (1)
0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!


Or Learn More in Our Blog >>