Splunk Enterprise

seperating arcsightlogs in heavyforwarder

sabaKhadivi
Path Finder

I decided to send some juniper and fortigate logs to an arcsight smart connector and then send its output to splunk heavy forwarder and then route them to different indexera based on their source( srx or fortigate) , is it possible when all the logs come from one arcsight host? whats the solution?

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

AI Adoption Hub Launch | Curated Resources to Get Started with AI in Splunk

Hey Splunk Practitioners and AI Enthusiasts! It’s no secret (or surprise) that AI is at the forefront of ...