I'm trying to set up the Splunk for A10 Networks app.
It expects syslog data on UDP port 514.
My data is collected by NXLog, spit out into a file, and then consumed by Splunk.
As such, I'm trying to edit a props.conf stanza in the app's directory from it's default, **[source::udp:514]** to match my file path.
Example path:
*D:\syslog\a10networks&adc_a10networks\[device name]\[file name].syslog*.
How would I construct my source stanza?
I've tried many variations along the lines of, **[source::D:\\...\\a10networks&adc_a10networks\\....syslog]** (I have tried escaping the ampersand in my path). I'm running Splunk on Windows if it matters.
↧