Splunk Search

How to configure network devices on splunk

tuhinbhowmick
New Member

Hi,

I am very new to this tool. I have just installed Splunk 6.0 and till now haven't add any data.

I want to use this tool for my DC Network infra monitoring. So, can you please help me out how to proceed further ?

Your quick ans would be really appreciable.

Regards,
Tuhin

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

Add a syslog data input, probably a UDP data input on port 514 with a default sourcetype of syslog. Turn on syslog at the Switch to send data to the Splunk server on that port.

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

Forwarders are a different download and are very lightweight: http://www.splunk.com/download/universalforwarder

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

Yes, install a Splunk Universal Forwarder on the syslog server and forward the events directly into Splunk. You will need to setup Splunk as a receiver on the default port of 9997 if you have not done so already. This is pretty much the standard way that all customers get data from a syslog server into Splunk.

0 Karma

tuhinbhowmick
New Member

We already have SYSLOG server. Is there any way SPLUNK can fetch data directly from SYSLOG server or we need to install SPLUNK on syslog server itself to analyze the data ?

Regards,
Tuhin

0 Karma

tuhinbhowmick
New Member

More specifically, how should I forward the Cisco Switch data directly to Splunk so that it can use those data for showing result.

I have read about Splunk Universal Forwarder to collect dat directly from endpoints. So, in that case if I want to get the data directly from my Cisco Switch to SPLUNK, then how to proceed ?

Regards,
Tuhin

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...