Hi,
we have the same issue and our Splunk admin followed the rules
but nevertheless all is seen as cisco:ios no difference for ios-xe or nx-os
splunk@xxx % tail -5 props.conf
[CC:syslog]
TRANSFORMS-force_sourcetypes_cc = force_sourcetype_cisco_asa, force_sourcetype_for_cisco_ios, force_sourcetype_for_cisco_ios-xr, force_sourcetype_for_cisco_ios-xe
SHOULD_LINEMERGE = false
KV_MODE = none
TZ = UTC
So any clue what's wrong ?
We had also updated App and Add-on to 2.5.8
Do I have to ask a new question or does this still fit to this post ?
... View more