Hi,
This assumes you're receiving not only wsa trough syslog but also other log types, also it assumes the logs are being sent in squid format.
On the indexer create an %SPLUNK_HOME%/etc/system/local/inputs.conf with:
[udp://514]
disabled=false
either on the same dir or on the local dir for the addon create a props.conf with:
[source::udp:514]
TRANSFORMS-change_cisco_wsa = set_sourcetype_cisco_wsa, set_index_cisco_wsa
and a local/transforms.conf with:
[set_sourcetype_cisco_wsa]
REGEX = :\d\d\s+(?:\d+\s+|(?:user|daemon|local.?)\.\w+\s+)*\[?(xxx.xxx.xxx.xxx|xxx.xxx.xxx.xxx)[\w\.\-]*\]?\s
FORMAT = sourcetype::cisco_wsa_squid
DEST_KEY = MetaData:Sourcetype
[set_index_cisco_wsa]
REGEX = :\d\d\s+(?:\d+\s+|(?:user|daemon|local.?)\.\w+\s+)*\[?(xxx.xxx.xxx.xxx|xxx.xxx.xxx.xxx)[\w\.\-]*\]?\s
DEST_KEY = _MetaData:Index
FORMAT = cisco
the xxx.xxx.xxx.xxx are IP addresses for the wsa interface sending the syslog.
The first transform sets the sourcetype, the second sets the index, in this case, cisco.
Hope this helps.
Cheers,
J.
... View more