Splunk Enterprise

seperating arcsightlogs in heavyforwarder

Path Finder

I decided to send some juniper and fortigate logs to an arcsight smart connector and then send its output to splunk heavy forwarder and then route them to different indexera based on their source( srx or fortigate) , is it possible when all the logs come from one arcsight host? whats the solution?

Tags (1)
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!