<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Not Receiving Logs From Splunk Forwarder or Syslog-ng what could be the issue with splunk enterprise? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627210#M107684</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252934"&gt;@tks_tman&lt;/a&gt;.,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jan 2023 07:30:19 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-01-16T07:30:19Z</dc:date>
    <item>
      <title>Splunk Not Receiving Logs From Splunk Forwarder or Syslog-ng what could be the issue with splunk enterprise?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627150#M107674</link>
      <description>&lt;P&gt;I have Splunk setup and it establishes connection with syslog and splunk universal forwarder from a remote server:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tks_tman_7-1673703578978.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23379i9945246A60C025FC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tks_tman_7-1673703578978.png" alt="tks_tman_7-1673703578978.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have syslog-ng setup as follows:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tks_tman_9-1673703608134.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23380i9FF49099441E88B2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tks_tman_9-1673703608134.png" alt="tks_tman_9-1673703608134.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tks_tman_11-1673703648538.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23381i33E6AB1860C3C6DD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tks_tman_11-1673703648538.png" alt="tks_tman_11-1673703648538.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You can see the connections established&lt;SPAN&gt;&amp;nbsp;:&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tks_tman_12-1673703678360.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23382iE8B340DA5C5A29CF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tks_tman_12-1673703678360.png" alt="tks_tman_12-1673703678360.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This is the inputs.conf for the splunk universal forwarder:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tks_tman_13-1673703704841.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23383i402881254DA8217E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tks_tman_13-1673703704841.png" alt="tks_tman_13-1673703704841.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But still no data is being received by splunk:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tks_tman_14-1673703729335.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23384i3BB2BFD59C5C56CF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tks_tman_14-1673703729335.png" alt="tks_tman_14-1673703729335.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to use some powershell script to verify that the logs were being sent and delivered to the server with splunk. The issue is with splunk itself.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tks_tman_0-1673746273537.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23387i4ECB6511CD95A386/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tks_tman_0-1673746273537.png" alt="tks_tman_0-1673746273537.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I missing something? And how would I go about troubleshooting the issue and fixing it?&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jan 2023 01:32:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627150#M107674</guid>
      <dc:creator>tks_tman</dc:creator>
      <dc:date>2023-01-15T01:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Not Receiving Logs From Splunk Forwarder or Syslog-ng what could be the issue with splunk enterprise?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627151#M107675</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252934"&gt;@tks_tman&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand: do you want to receive logs from a linux machine where the universal forwarder is installed or do you want to receive logs using syslog?&lt;/P&gt;&lt;P&gt;You spoke of port 9997 that's used&amp;nbsp;&amp;nbsp;to receive data from a Universal Forwarder installed on another machine and not to receive syslogs.&lt;/P&gt;&lt;P&gt;In this case you don't need syslogs and inputs.conf that you displayed must be located on the Universal Forwarder not in the Splunk server.&lt;/P&gt;&lt;P&gt;If instead you need to receive syslogs, you don't need the inputs.conf you displayed and the 9997 port enabling, but you have to enable a network input using the protocol (UDP/TCP) you prefer.&lt;/P&gt;&lt;P&gt;You don't need also syslog-ng server.&lt;/P&gt;&lt;P&gt;If you want to use syslog-ng server to receive syslogs, you have to enable it ro receive remote syslogs and wring data on file system; then you need an inputs.conf (different from the one you displayed) to read the text files created by syslog-ng.&lt;/P&gt;&lt;P&gt;So wjhat's your requiremen??&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 14 Jan 2023 15:54:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627151#M107675</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-14T15:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Not Receiving Logs From Splunk Forwarder or Syslog-ng what could be the issue with splunk enterprise?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627152#M107676</link>
      <description>&lt;P&gt;Apart from all the questions &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; asked, remember that if you simply set your syslog server to forward the events to splunk server's 9997 port, it won't work. Splunk expects s2s communication on 9997, not plain syslog.&lt;/P&gt;&lt;P&gt;Question is whether you're getting anything received by your syslog-ng daemon at all. Does anything get written into the files in /var/log/remote?&lt;/P&gt;&lt;P&gt;Do you in fact get anything in on the 514 port?&lt;/P&gt;&lt;P&gt;Did you verify it in any way?&lt;/P&gt;</description>
      <pubDate>Sat, 14 Jan 2023 16:04:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627152#M107676</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-01-14T16:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Not Receiving Logs From Splunk Forwarder or Syslog-ng what could be the issue with splunk enterprise?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627156#M107677</link>
      <description>&lt;P&gt;Yes. I am certain that the local logs are generated. What do you mean by "splunk expects s2s communication on 9997"? Does it require some conversion? How would I go about doing that?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 953px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23385i1519A8AB48CBE88E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Jan 2023 21:26:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627156#M107677</guid>
      <dc:creator>tks_tman</dc:creator>
      <dc:date>2023-01-14T21:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Not Receiving Logs From Splunk Forwarder or Syslog-ng what could be the issue with splunk enterprise?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627158#M107678</link>
      <description>&lt;P&gt;The logs are being sent from a remote device to-&amp;gt; a linux machine (that contains splunk universal forwarder and syslog-ng) ( and stores logs locally) both of these are to send the logs to -&amp;gt; splunk.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk seems to not be accepting the logs from either syslog-ng or the splunk universal forwarder even though the tcp connections are established between both syslog-ng and splunk and splunk universal forwarder and splunk.&lt;/P&gt;&lt;P&gt;The requirement is splunk isn't accepting the logs even though the connections are established.&lt;/P&gt;&lt;P&gt;I also get the following message with the list forward-server command:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tks_tman_0-1673732441766.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/23386i2E8A5C2E33C3B76D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tks_tman_0-1673732441766.png" alt="tks_tman_0-1673732441766.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Jan 2023 21:41:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627158#M107678</guid>
      <dc:creator>tks_tman</dc:creator>
      <dc:date>2023-01-14T21:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Not Receiving Logs From Splunk Forwarder or Syslog-ng what could be the issue with splunk enterprise?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627165#M107679</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252934"&gt;@tks_tman&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;debug the problem one by one:&lt;/P&gt;&lt;P&gt;are you receiving internal Splunk logs from the forwarder? you can check this with a simple search&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=&amp;lt;your_host&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;If yes the problem in in inputs.conf.&lt;/P&gt;&lt;P&gt;In this case in the inputs.conf stanza you have to put the path of the files (written by the syslog-ng server) logs to read and not the "/var/log" path:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///&amp;lt;your_data_path&amp;gt;/&amp;lt;your file_name&amp;gt;]&lt;/LI-CODE&gt;&lt;P&gt;If not the problem cound be:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;in outputs.conf on the Forwarder,&lt;/LI&gt;&lt;LI&gt;in an intermediate Firewall,&lt;/LI&gt;&lt;LI&gt;in the local Firewall.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;What's your outputs.conf?&lt;/P&gt;&lt;P&gt;for more infos see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/9.0.3/Forwarder/Configureforwardingwithoutputs.conf" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/9.0.3/Forwarder/Configureforwardingwithoutputs.conf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it should be something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[tcpout]
defaultGroup=my_indexers

[tcpout:my_indexers]
server=mysplunk_indexer1:9997, mysplunk_indexer2:9996

[tcpout-server://mysplunk_indexer1:9997]
[tcpout-server://mysplunk_indexer2:9997]&lt;/LI-CODE&gt;&lt;P&gt;To troubleshooting Firewalls, use telnet, from the Forwarder:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;telnet &amp;lt;ip_splunk_server&amp;gt; 9997&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 15 Jan 2023 07:04:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627165#M107679</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-15T07:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Not Receiving Logs From Splunk Forwarder or Syslog-ng what could be the issue with splunk enterprise?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627210#M107684</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252934"&gt;@tks_tman&lt;/a&gt;.,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 07:30:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627210#M107684</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-01-16T07:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Not Receiving Logs From Splunk Forwarder or Syslog-ng what could be the issue with splunk enterprise?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627214#M107685</link>
      <description>&lt;P&gt;OK. For the rest of debugging &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; already pointed you in the right way. I'll just drop in a few words about this 9997 port.&lt;/P&gt;&lt;P&gt;Port 9997/TCP is used by S2S (splunk to splunk) communication. That is a protocol which is used to forward events from a source splunk machine (typically a forwarder) to a receiving splunk machine (might be an indexer but might be an intermediate forwarder). It is a proprietary protocol and is used only for connectivity between splunk components. So you can't just point your syslog server to send events to splunk server on 9997 and expect it to receive it properly.&lt;/P&gt;&lt;P&gt;As a side note - even though you can set up an input of tcp:// or udp:// type on your splunk forwarder to listen for raw syslog data sent from your sources, you typically don't want to do that. You'd rather use an intermediate syslog server (like you're doing here with syslog-ng writing to files which are then picked up by the UF).&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 08:34:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Not-Receiving-Logs-From-Splunk-Forwarder-or-Syslog-ng/m-p/627214#M107685</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-01-16T08:34:42Z</dc:date>
    </item>
  </channel>
</rss>

