Splunk Enterprise Security

How do I configure Splunk to monitor network traffic on Juniper devices?

chinuakatchy
Explorer

Hello.

I want to monitor the network traffic in my Company using Splunk. I have configured Splunk to read syslog traffic on various devices, but I believe there's more to it as far as network monitoring is concerned.

I would like to know the step by step process to configure my Juniper routers, switches, and firewalls especially the SPAN/mirror port configuration.

Early response is highly appreciated. I have much regards.

mstjohn_splunk
Splunk Employee
Splunk Employee

hi @chinuakatchy

Did either of the answers below solve your problem? If so, please resolve this post by approving the one that helped you the most! If your problem is still not solved, keep us updated so that someone else can help ya. Thanks for posting!

0 Karma

jwhughes58
Contributor

In http://docs.splunk.com/Documentation/AddOns/released/Juniper/Setup are the links to Juniper documentation on how to configure syslog.

0 Karma

chinuakatchy
Explorer

I have already configured my devices to forward syslog to Splunk. However, I also want Splunk to capture the raw network traffic.

0 Karma

rajneeshc1981
Explorer

configure it through syslog-ng

0 Karma

chinuakatchy
Explorer

I have already configured my devices to forward syslog to Splunk. However, I also want Splunk to capture the raw network traffic.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...