Getting Data In

how to monitor network logs

surekhasplunk
Communicator

Hi,

I have cisco, checkpoint, fortinet, arista, pulse secure etc devices which needs to be monitored for network, bandwidth, packet drops usage etc.

So what would be the best approach to achieve it. Which app i should use

Thanks

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

No one app will handle all of those devices. Look in apps.splunk.com for apps that support the products you use.

Just installing apps may not be enough. Apps will process logs, but don't always fetch the logs themselves. You probably will have to configure the devices to send their logs in syslog format to a syslog server. Then install the Splunk Universal Forwarder on the syslog server to pass the logs to Splunk. See http://www.georgestarcher.com/splunk-success-with-syslog/.

What you can monitor for depends on the data provided to Splunk by your devices. For instance, you can't look for packet drops if packet drops are not logged.

This is a very general question. Feel free to post new, specific questions as you go.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

No one app will handle all of those devices. Look in apps.splunk.com for apps that support the products you use.

Just installing apps may not be enough. Apps will process logs, but don't always fetch the logs themselves. You probably will have to configure the devices to send their logs in syslog format to a syslog server. Then install the Splunk Universal Forwarder on the syslog server to pass the logs to Splunk. See http://www.georgestarcher.com/splunk-success-with-syslog/.

What you can monitor for depends on the data provided to Splunk by your devices. For instance, you can't look for packet drops if packet drops are not logged.

This is a very general question. Feel free to post new, specific questions as you go.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...