<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot transfer rsyslog to Splunk. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Cannot-transfer-rsyslog-to-Splunk/m-p/54387#M10525</link>
    <description>&lt;P&gt;Sorry, this may be caused by a rsyslog client configuration.&lt;BR /&gt;
There are nothing captured by tcpdump (port 2000) on hostB.&lt;BR /&gt;
Telnet connections from hostA to hostB is able.&lt;/P&gt;

&lt;P&gt;I know that UF is better than TCP transfer, but not always able to install.....&lt;/P&gt;

&lt;P&gt;I confirmed that TCP/514 is able to transfer logs, but other ports is not.&lt;/P&gt;</description>
    <pubDate>Fri, 08 Mar 2013 01:56:09 GMT</pubDate>
    <dc:creator>sunrise</dc:creator>
    <dc:date>2013-03-08T01:56:09Z</dc:date>
    <item>
      <title>Cannot transfer rsyslog to Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cannot-transfer-rsyslog-to-Splunk/m-p/54383#M10521</link>
      <description>&lt;P&gt;May be it's easy but I got bogged down. Please help me.&lt;/P&gt;

&lt;P&gt;I want to transfer rsyslog(hostA) to splunk(hostB) in TCP.&lt;BR /&gt;
So I set the following configurations but I can't.&lt;/P&gt;

&lt;P&gt;( inputs.conf@hostB )&lt;BR /&gt;
[tcp://2000]&lt;BR /&gt;
connection_host = dns&lt;BR /&gt;
sourcetype = syslog&lt;/P&gt;

&lt;P&gt;( rsyslog.conf@hostA )&lt;BR /&gt;
*.info;mail.none;authpriv.none;cron.none                @@hostB:2000&lt;/P&gt;

&lt;P&gt;I confirmed /etc/hosts file is correct, and port 2000 is "LISTEN" state,&lt;BR /&gt;
and both firewall is down. &lt;/P&gt;

&lt;P&gt;I think that Splunk is waiting as a TCP receiver and some syslogd transer the logs to that.&lt;BR /&gt;
Is it wrong ?&lt;BR /&gt;
Other configuration is needed ? &lt;/P&gt;

&lt;P&gt;Thank you for helping.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2013 11:08:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cannot-transfer-rsyslog-to-Splunk/m-p/54383#M10521</guid>
      <dc:creator>sunrise</dc:creator>
      <dc:date>2013-03-07T11:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot transfer rsyslog to Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cannot-transfer-rsyslog-to-Splunk/m-p/54384#M10522</link>
      <description>&lt;P&gt;Have you run tcpdump or similar on hostB to check that you're actually receiving data on port TCP/2000?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2013 11:21:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cannot-transfer-rsyslog-to-Splunk/m-p/54384#M10522</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-03-07T11:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot transfer rsyslog to Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cannot-transfer-rsyslog-to-Splunk/m-p/54385#M10523</link>
      <description>&lt;P&gt;in addition to Ayn's suggestion: have to tried to connect to hostB's port 2000 by using on hostA 'telnet hostB 2000' for example?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2013 12:26:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cannot-transfer-rsyslog-to-Splunk/m-p/54385#M10523</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2013-03-07T12:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot transfer rsyslog to Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cannot-transfer-rsyslog-to-Splunk/m-p/54386#M10524</link>
      <description>&lt;P&gt;I would actually recommand to install a UF on host A that reads the rsyslog locally and send it to HostB...&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2013 14:13:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cannot-transfer-rsyslog-to-Splunk/m-p/54386#M10524</guid>
      <dc:creator>OL</dc:creator>
      <dc:date>2013-03-07T14:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot transfer rsyslog to Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cannot-transfer-rsyslog-to-Splunk/m-p/54387#M10525</link>
      <description>&lt;P&gt;Sorry, this may be caused by a rsyslog client configuration.&lt;BR /&gt;
There are nothing captured by tcpdump (port 2000) on hostB.&lt;BR /&gt;
Telnet connections from hostA to hostB is able.&lt;/P&gt;

&lt;P&gt;I know that UF is better than TCP transfer, but not always able to install.....&lt;/P&gt;

&lt;P&gt;I confirmed that TCP/514 is able to transfer logs, but other ports is not.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2013 01:56:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cannot-transfer-rsyslog-to-Splunk/m-p/54387#M10525</guid>
      <dc:creator>sunrise</dc:creator>
      <dc:date>2013-03-08T01:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot transfer rsyslog to Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cannot-transfer-rsyslog-to-Splunk/m-p/54388#M10526</link>
      <description>&lt;P&gt;On the indexer set up rsyslog or syslog-ng and configure it to listen on tcp 2000 also configure syslog to write to files for the indexer to read those files.  This is actually the preferred method over receiving on a port using Splunk.  &lt;/P&gt;

&lt;P&gt;It's not that hard to configure and you can also filter easier.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.rsyslog.com/receiving-messages-from-a-remote-system/"&gt;http://www.rsyslog.com/receiving-messages-from-a-remote-system/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can then have multiple systems set syslog to that server and written to files to be monitored.&lt;/P&gt;

&lt;P&gt;A basic example in syslog-ng receiving would be: &lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
source s_net { tcp(port(2000)) };&lt;BR /&gt;
filter f_filtername { set(filters_here); };&lt;BR /&gt;
destination d_filterdest { file("/var/log/remote/$HOST/sourcetype/log.log"); };&lt;BR /&gt;
log {&lt;BR /&gt;
    source(s_net);&lt;BR /&gt;
    filter(f_filtername);&lt;BR /&gt;
    destination(d_filterdest);&lt;BR /&gt;
};&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;On the Splunk indexer the monitor example:&lt;/P&gt;

&lt;P&gt;.../local/inputs.conf&lt;BR /&gt;
&lt;CODE&gt;&lt;BR /&gt;
[monitor:///var/log/*/sourcetype/log.log]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
sourcetype = your_sourcetype&lt;BR /&gt;
host_segment = 3&lt;BR /&gt;
index = your_index&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2013 02:38:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cannot-transfer-rsyslog-to-Splunk/m-p/54388#M10526</guid>
      <dc:creator>jgedeon120</dc:creator>
      <dc:date>2013-03-08T02:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot transfer rsyslog to Splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cannot-transfer-rsyslog-to-Splunk/m-p/54389#M10527</link>
      <description>&lt;P&gt;Thank you, everyone. I've solved the problem.&lt;BR /&gt;
The environments details that CentOS6.2 (hostA, hostB), and rsyslogd 5.8.10.&lt;BR /&gt;
I edit /etc/sysconfig/rsyslog like below.&lt;/P&gt;

&lt;P&gt;SYSLOGD_OPTIONS="-c 5 -f /etc/rsyslog.conf"&lt;/P&gt;

&lt;P&gt;And I can transfer logs with changed TCP port number.&lt;BR /&gt;
Thank you for your advice.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2013 11:27:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cannot-transfer-rsyslog-to-Splunk/m-p/54389#M10527</guid>
      <dc:creator>sunrise</dc:creator>
      <dc:date>2013-03-08T11:27:41Z</dc:date>
    </item>
  </channel>
</rss>

