You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Note: If your issue is not a bug or a feature request, please raise a support ticket through our support portal (Splunk.com > Support > Support Portal). This will help us resolve your issue more efficiently and provide you with better assistance. For more information on how to work with the Splunk Support, please refer to this guide.
What is the sc4s version?
v3.32 Is there a pcap available? If so, would you prefer to attach it to this issue or send it to Splunk support?
Yes, attached pcap and raw events to splunk support case# 3604963 What the vendor name?
Lantronix What's the product name?
ConsoleFlow If you're requesting support for a new vendor, do you have any preferences regarding the default index and sourcetype for their events?
Do you have syslog documentation or a manual for that device??
Feature Request description:
Do you want to have it for local usage or prepare a github PR?
The text was updated successfully, but these errors were encountered:
After analyzing the pcap logs, we found that the "program" field consistently has a prefix of "SLC-SLB" across all logs (e.g., "SLC-SLB/xcflow," "SLC-SLB/xld," "SLC-SLB/xasd"). Using this prefix, we’ve developed a parser to filter logs with "SLC-SLB" in the program field. For these logs, we’ve set the metadata as follows: source is "Lantronix:ConsoleFlow," sourcetype is "Lantronix:ConsoleFlow:syslog," and index is "netops."
Pleas modify any of these values if required in your local env.
To add the parser to your local environment:
Navigate to: /opt/sc4s/local/config/app_parsers
Create a new file named: app-syslog-lantronix_consoleflow.conf
Note: If your issue is not a bug or a feature request, please raise a support ticket through our support portal (Splunk.com > Support > Support Portal). This will help us resolve your issue more efficiently and provide you with better assistance. For more information on how to work with the Splunk Support, please refer to this guide.
What is the sc4s version?
v3.32
Is there a pcap available? If so, would you prefer to attach it to this issue or send it to Splunk support?
Yes, attached pcap and raw events to splunk support case# 3604963
What the vendor name?
Lantronix
What's the product name?
ConsoleFlow
If you're requesting support for a new vendor, do you have any preferences regarding the default index and sourcetype for their events?
Do you have syslog documentation or a manual for that device??
Feature Request description:
Do you want to have it for local usage or prepare a github PR?
The text was updated successfully, but these errors were encountered: