Hi @btsmerchstor78, the Juniper_TA makes transformations and sourcetype override, so you have to install the TA also on your on-premise HF that's the first full Splunk instance that your Juniper data passing through. By default in the TA there isn't any input, so in your input you have to assign the sourcetype "juniper" to your data source, so the add-on takes these logs and makes a transformation assigning the correct sourcetypes and parsing rules. It's important that the input you enabled is done following the instructions of the above documentation. Ciao. Giuseppe
... View more