Hello Members,
I have a basic question - I am not sure how to get data into splunk, into a custom index, use a source type, and then exrract fields. I have the add-0n installed for Cisco network devices, but not sure it is the correct app to use for my case.
I have a remote syslog server (running rsyslog) that builds log files for cisco switches and routers.
I have a universal forwarder installed on the syslog server, it forwards data to splunk IF I configure it
correctly. I have tried configuring the Splunk receiver two ways: one using the "Forwarding and receiving" option from the "DATA" area - this works - but only allows showing data from the host sending the log info. And uses only 1 port, I am using 9997.
I have not seen how to set a data source or source type for the incoming data.
The second way seems to be using the "Data Inputs" part of the "DATA" area. This seems to not be possible, as the data is coming from a Universaly forwarder not a Splunk Enterprise configured as a forwarder.
How can I assign a source type and index to the data that does come in from the host that is configured with port 997 as a receiver? Sorry for such a confusing question,
Regards,
eholz1
... View more