<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog from Firewall issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-Firewall-issue/m-p/53904#M10399</link>
    <description>&lt;P&gt;Used the SoS app&lt;/P&gt;

&lt;P&gt;This app will show you&lt;/P&gt;

&lt;P&gt;S.o.S - Splunk on Splunk &amp;gt; Metrics &amp;gt; Incoming Network Throughput&lt;/P&gt;

&lt;P&gt;this shows the network data comeing into splunk on what ports&lt;/P&gt;

&lt;P&gt;After checking with my lunix admin and looking in SoS I confrunted the firewall guy and they did not make the change requiered.&lt;/P&gt;</description>
    <pubDate>Fri, 20 Jan 2012 20:08:47 GMT</pubDate>
    <dc:creator>hartfoml</dc:creator>
    <dc:date>2012-01-20T20:08:47Z</dc:date>
    <item>
      <title>Syslog from Firewall issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-Firewall-issue/m-p/53902#M10397</link>
      <description>&lt;P&gt;I asked my Firewall admin to change the port for syslog to the Splunk indexer.&lt;/P&gt;

&lt;P&gt;He changed it from 514 to 1514.&lt;/P&gt;

&lt;P&gt;He said he made the change but I am not seeing the incoming log data.&lt;/P&gt;

&lt;P&gt;I'm sure the indexer host firewall port is open.&lt;/P&gt;

&lt;P&gt;Where would I go to see what data is coming in on what port?&lt;/P&gt;

&lt;P&gt;Does splunk tag the data with the indexer connection information?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2012 20:15:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-Firewall-issue/m-p/53902#M10397</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2012-01-18T20:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog from Firewall issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-Firewall-issue/m-p/53903#M10398</link>
      <description>&lt;P&gt;The low-impact way would be to get IP accounting or netflow data from any routers or switches between the firewall and your indexer.&lt;/P&gt;

&lt;P&gt;Otherwise you could install packet capture software (Wireshark or Microsoft Network Monitor, for example) on your indexer and capture all of the traffic that's hitting its network port.&lt;/P&gt;

&lt;P&gt;If you can get a SPAN port set up (it sends a copy of all traffic heading for one switch port to a second port) then you can install the packet capture software on any machine and avoid touching your indexer.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2012 07:33:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-Firewall-issue/m-p/53903#M10398</guid>
      <dc:creator>FunPolice</dc:creator>
      <dc:date>2012-01-19T07:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog from Firewall issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-Firewall-issue/m-p/53904#M10399</link>
      <description>&lt;P&gt;Used the SoS app&lt;/P&gt;

&lt;P&gt;This app will show you&lt;/P&gt;

&lt;P&gt;S.o.S - Splunk on Splunk &amp;gt; Metrics &amp;gt; Incoming Network Throughput&lt;/P&gt;

&lt;P&gt;this shows the network data comeing into splunk on what ports&lt;/P&gt;

&lt;P&gt;After checking with my lunix admin and looking in SoS I confrunted the firewall guy and they did not make the change requiered.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2012 20:08:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-from-Firewall-issue/m-p/53904#M10399</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2012-01-20T20:08:47Z</dc:date>
    </item>
  </channel>
</rss>

