The App doesn't seem to track back to the data from the Juniper logs. Our data is source="syslog" from our Juniper boxes, how do we tie this back to the Junipe SA App for the field extractions?
asked 07 Nov '12, 18:27
The Juniper SA app expects the sourcetype of the data (for field extractions, etc) to work to be "juniper_sa_log". If you've got it branded as "syslog", then the rules that apply to the Juniper SA app won't be triggered. You can consider renaming the sourcetype if the Juniper data is the only thing coming in from syslog. Otherwise, you'll want to apply the "sa_sourcetyper_rule" to your incoming data. The existing rule looks like this:
[source::udp:514] TRANSFORMS-sasourcetype = sa_sourcetyper
You'll want to write something like this in your props.conf:
[syslog] TRANSFORMS-sasourcetype = sa_sourcetyper
answered 07 Nov '12, 19:22