Hi @dm1 , until today, I always used the second one in many hundreds of project without any issue. the fact that it isn't unsupported it's a new for me, but probably it was an oversight of mine. The first one is Cisco supported so you could use it. About instuctions for ingestion, I'm not a network specialist, but Catalysts, as other network appliances, should send their logs by syslog, so you can directly receive syslogs using Splunk, in an Heavy Forwarder, or (better),creating an rsyslog input that writes syslogs in a file that it is read by Splunk. Ciao. Giuseppe
... View more