Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Juniper sourcetype #2544

Closed
n0068702 opened this issue Aug 1, 2024 · 8 comments
Closed

Juniper sourcetype #2544

n0068702 opened this issue Aug 1, 2024 · 8 comments
Assignees
Labels
enhancement New feature or request

Comments

@n0068702
Copy link

n0068702 commented Aug 1, 2024

What is the sc4s version?
version = "3.4.2"

Is there a pcap available? If so, would you prefer to attach it to this issue or send it to Splunk support?
?

What the vendor name?
Juniper

What's the product name?
firewall

If you're requesting support for a new vendor, do you have any preferences regarding the default index and sourcetype for their events?

index = juniper_admin
sourcetypes = juniper:junos:admin
junos:firewall

Do you have syslog documentation or a manual for that device??

Feature Request description:

Need to add these sourcetypes to sc4s vendor

Do you want to have it for local usage or prepare a github PR?

@cwadhwani-splunk cwadhwani-splunk self-assigned this Aug 5, 2024
@cwadhwani-splunk
Copy link
Collaborator

Hi @n0068702
Could you please create a support ticket and share the sample logs or the pcap file over that ticket? This will help us move forward with this case.

Thanks.

@n0068702
Copy link
Author

n0068702 commented Aug 6, 2024 via email

@cwadhwani-splunk
Copy link
Collaborator

Hi @n0068702
Here are a couple of links that can help you to get the raw logs/pcap file:

Please feel free to reach out to support if you need any further help with the PCAP file.

@n0068702
Copy link
Author

n0068702 commented Aug 7, 2024 via email

@cwadhwani-splunk
Copy link
Collaborator

Hi @n0068702
I have requested the support team to assist you with generating the pcap file. They will get in touch with you for the same.

@cwadhwani-splunk
Copy link
Collaborator

Hi @n0068702

Could you please confirm if the call is solely for generating the pcap file, or if you need assistance with any other issues as well? This will help the support team prepare accordingly.

Note: For now, we just need the pcap file or sample raw logs to proceed with the case.

@Ruthieb-splunk
Copy link

Hi @cwadhwani-splunk, I'm the Splunk TSE working with the customer on the support side. SFDC case: 3533537.
We already had a call and I guided the customer on how to collect the pcap we need to create the sourcetype.
Once I have the file on the case I will share it with you.

@cwadhwani-splunk cwadhwani-splunk added the enhancement New feature or request label Aug 14, 2024
@cwadhwani-splunk
Copy link
Collaborator

Closing this GitHub issue, due to unavailability of the PCAP file. If not already resolved, please feel free to reopen this case once a support ticket is created with the PCAP file attached. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants