I have two Cisco SG500 switches and I'd like to get them logging to splunk. What is the best method? I can't find a premade dashboard, nor source connector when adding a port.
Hi cbruder239,
you have to put Splunk in waiting on 514 port, UDP protocol and then configure your switch to send logs to your Indexer using syslog.
Put attention on two points:
Bye.
Giuseppe