<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor Cyberoam 35iNG in Security</title>
    <link>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45988#M1508</link>
    <description>&lt;P&gt;I have configured it via tcp and udp port 514 still i am waiting for logs.&lt;/P&gt;</description>
    <pubDate>Mon, 26 Aug 2013 14:31:43 GMT</pubDate>
    <dc:creator>nilesh8</dc:creator>
    <dc:date>2013-08-26T14:31:43Z</dc:date>
    <item>
      <title>Monitor Cyberoam 35iNG</title>
      <link>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45981#M1501</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;How to configure splunk 5.0 to monitor Cyberoam 35iNG firewall.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2013 12:00:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45981#M1501</guid>
      <dc:creator>nilesh8</dc:creator>
      <dc:date>2013-08-26T12:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Cyberoam 35iNG</title>
      <link>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45982#M1502</link>
      <description>&lt;P&gt;Hi nilesh8.&lt;/P&gt;

&lt;P&gt;I'm not familiar with that particular firewall, but I'm assuming that it is capable of sending Syslog messages.&lt;/P&gt;

&lt;P&gt;You can configure Splunk to accept Syslog messages by following the steps in this link: &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/SyslogUDP"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/SyslogUDP&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2013 12:12:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45982#M1502</guid>
      <dc:creator>rturk</dc:creator>
      <dc:date>2013-08-26T12:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Cyberoam 35iNG</title>
      <link>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45983#M1503</link>
      <description>&lt;P&gt;Hi Turk,&lt;BR /&gt;
Thanks for reply. I have configured it via syslog udp port 514. But i am not able to see any logs in splunk also not show the connection in 'netstat' command.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2013 12:36:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45983#M1503</guid>
      <dc:creator>nilesh8</dc:creator>
      <dc:date>2013-08-26T12:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Cyberoam 35iNG</title>
      <link>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45984#M1504</link>
      <description>&lt;P&gt;A few things I'd check:&lt;BR /&gt;
- Ensure Syslog is being sent by TCP not UDP&lt;BR /&gt;
- Temporarily disable the server firewall on the Splunk server to see whether that's a factor&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2013 12:40:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45984#M1504</guid>
      <dc:creator>rturk</dc:creator>
      <dc:date>2013-08-26T12:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Cyberoam 35iNG</title>
      <link>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45985#M1505</link>
      <description>&lt;P&gt;I have configured it by TCP port and also disabled server firewall but still not see any logs on splunk&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2013 13:46:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45985#M1505</guid>
      <dc:creator>nilesh8</dc:creator>
      <dc:date>2013-08-26T13:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Cyberoam 35iNG</title>
      <link>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45986#M1506</link>
      <description>&lt;P&gt;Ahhh one other point I forgot to mention, have you confirmed that Splunk is set up to receive TCP 514? &lt;BR /&gt;
- Manager &amp;gt; Data Inputs &amp;gt; TCP &amp;gt; Add New&lt;BR /&gt;
You might want to do the same for UDP just to be sure.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2013 13:50:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45986#M1506</guid>
      <dc:creator>rturk</dc:creator>
      <dc:date>2013-08-26T13:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Cyberoam 35iNG</title>
      <link>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45987#M1507</link>
      <description>&lt;P&gt;I have configured it with TCP 514 only&lt;BR /&gt;
TCP port = 514&lt;BR /&gt;
Source type = syslog&lt;BR /&gt;
Status = Enabled&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2013 14:20:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45987#M1507</guid>
      <dc:creator>nilesh8</dc:creator>
      <dc:date>2013-08-26T14:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Cyberoam 35iNG</title>
      <link>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45988#M1508</link>
      <description>&lt;P&gt;I have configured it via tcp and udp port 514 still i am waiting for logs.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2013 14:31:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45988#M1508</guid>
      <dc:creator>nilesh8</dc:creator>
      <dc:date>2013-08-26T14:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Cyberoam 35iNG</title>
      <link>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45989#M1509</link>
      <description>&lt;P&gt;My only other suggestions at this point would be to narrow down the possible cause:&lt;BR /&gt;
- Redirect a device/server with a known-good syslog generation at Splunk&lt;BR /&gt;
- Point your firewall at a known/good syslog collector&lt;BR /&gt;
- Look at the event in $SPLUNK_HOME/var/log/splunk/splunkd.log to see any potential issues&lt;/P&gt;

&lt;P&gt;Everything you've mentioned indicates you've set it up correctly, so it's time for troubleshooting now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2013 00:36:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45989#M1509</guid>
      <dc:creator>rturk</dc:creator>
      <dc:date>2013-08-27T00:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Cyberoam 35iNG</title>
      <link>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45990#M1510</link>
      <description>&lt;P&gt;I have found following entries in splunk log&lt;BR /&gt;
08-26-2013 04:22:05.656 -0700 INFO  TcpInputConfig - performing DNS lookup on 192.168.2.1&lt;/P&gt;

&lt;P&gt;Also i tried it to configure via SNMP and found below log&lt;BR /&gt;
CarrierError: bind() for (u'192.168.2.1', 162) failed: [Errno 10049] The requested address is not valid in its context&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2013 06:00:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Monitor-Cyberoam-35iNG/m-p/45990#M1510</guid>
      <dc:creator>nilesh8</dc:creator>
      <dc:date>2013-08-28T06:00:51Z</dc:date>
    </item>
  </channel>
</rss>

