Getting Data In

How to feed syslog of another Cisco device to Splunk?

splunkbeginner
Engager

There are two Cisco devices; I call them “1st IP” and “2nd IP” hereafter.

I have managed to configured and send syslog of “1st IP” to Splunk. Please see following 2 screenshots.
alt text

Now i would like to another Cisco device, i.e. “2nd IP” to Splunk, by adding the “2nd IP”. It turned out to be weird to me.

All i wanted is something like this by always using soucetype:cisco, if possible:
UDP port---------------------souce type
192.168.1stIP:514-------- cisco
192.168.2ndIP:514--------cisco

alt text

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...