Splunk Enterprise Security

Zscaler add-on field extraction

bhsakarchourasi
Path Finder

Hi All,

We receiving zscaler logs on syslog server from there forwarder is reading logs and sending to Splunk cloud.

Zscaler add on is installed on forwarder as well as on search head but the log field extraction is not as expected.

just want to know if anyone has faced such issue with zscaler add on, if yes than how to resolve it.

Thanks,
Bhaskar

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...