I am trying to send Cisco SD-WAN router logs to Splunk Cloud. I have installed Universal forwarder on the log server running syslog-ng and am able to forward text-based logs. However, the FW logs are output in HSL, and it's in netflow ver.9 format.
How can I get this type of data in Splunk Cloud ?
Netflow is for flow reporting. You need Splunk Stream
https://docs.splunk.com/Documentation/StreamApp/latest/DeployStreamApp/AboutSplunkStream
Thanks for the advice.
My Splunk Cloud trial account has expired, so I will try it when I get a chance.