Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix/cisco meraki update #2137

Merged
merged 6 commits into from
Aug 14, 2023
Merged

Fix/cisco meraki update #2137

merged 6 commits into from
Aug 14, 2023

Conversation

mstopa-splunk
Copy link
Contributor

@mstopa-splunk mstopa-splunk commented Aug 11, 2023

In issue #2088 a user requested updating Meraki parser from community TA to Splunk supported TA.

Current production Meraki parser is based on vendor product by source configuration due to its general log format. There is also this note in the documentation:

The current TA does not sub sourcetype or utilize source preventing segmentation into more appropriate indexes

However, official Splunk TA for Cisco Meraki assigns various sourcetypes.

This PR retains previous solution for general Meraki logs, but also introduces syslog-app and almost-syslog-app parsers with sourcetypes corresponding to the new TA whenever hostname and program value enable it.

@rjha-splunk rjha-splunk merged commit c33cac9 into main Aug 14, 2023
5 of 8 checks passed
@rjha-splunk rjha-splunk deleted the fix/cisco-meraki-update branch August 14, 2023 12:25
@github-actions github-actions bot locked and limited conversation to collaborators Aug 14, 2023
@srv-rr-github-token
Copy link
Contributor

🎉 This PR is included in version 3.2.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants