<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No events ingested via HEC from Syslog Connector for Splunk (SC4S) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/No-events-ingested-via-HEC-from-Syslog-Connector-for-Splunk-SC4S/m-p/652362#M110754</link>
    <description>&lt;P&gt;I also add a tcpdump taken from the SC4S, I forced pings and curls to 443, those seem to work.&lt;/P&gt;&lt;P&gt;all the other lines are the attempts to connect to 8088 , called radan-http (?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jul 2023 11:53:22 GMT</pubDate>
    <dc:creator>corti77</dc:creator>
    <dc:date>2023-07-28T11:53:22Z</dc:date>
    <item>
      <title>No events ingested via HEC from Syslog Connector for Splunk (SC4S)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-events-ingested-via-HEC-from-Syslog-Connector-for-Splunk-SC4S/m-p/652361#M110753</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I had Splunk 9.05 and Syslog Conector for Splunk&amp;nbsp; (SC4S) 1.110 running and working for months. I just realized that there are not events ingested via HEC since two weeks ago.&lt;/P&gt;&lt;P&gt;Both servers are in the same subnet, no firewall in between.&lt;/P&gt;&lt;P&gt;- Local firewall of the server has a rule for the incoming TCP 8088 traffic. (screenshot attached)&lt;/P&gt;&lt;P&gt;- HEC enabled (global settings screenshot attached)&lt;/P&gt;&lt;P&gt;- HEC token is correct. It is the same in the SC4S and Splunk.&lt;/P&gt;&lt;P&gt;- netstat in the Splunk server shows listening in the port 8088. (attached)&lt;/P&gt;&lt;P&gt;- ping from SC4S to Splunk and curl on port splunk:80 works fine, if I do port splunk:8088 it throws a timeout. (attached)&lt;/P&gt;&lt;P&gt;- local firewall in SC4S&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;firewall-cmd --list-all&lt;BR /&gt;drop (active)&lt;BR /&gt;target: DROP&lt;BR /&gt;icmp-block-inversion: yes&lt;BR /&gt;interfaces: eth0&lt;BR /&gt;sources:&lt;BR /&gt;services: ssh syslog syslog-tls&lt;BR /&gt;ports: 514/tcp 601/tcp&lt;BR /&gt;protocols:&lt;BR /&gt;forward: no&lt;BR /&gt;masquerade: no&lt;BR /&gt;forward-ports:&lt;BR /&gt;source-ports:&lt;BR /&gt;icmp-blocks: echo-reply echo-request port-unreachable time-exceeded&lt;BR /&gt;rich rules:&lt;/P&gt;&lt;P&gt;any idea what else I could check?&lt;/P&gt;&lt;P&gt;many thanks&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 11:42:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-events-ingested-via-HEC-from-Syslog-Connector-for-Splunk-SC4S/m-p/652361#M110753</guid>
      <dc:creator>corti77</dc:creator>
      <dc:date>2023-07-28T11:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: No events ingested via HEC from Syslog Connector for Splunk (SC4S)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-events-ingested-via-HEC-from-Syslog-Connector-for-Splunk-SC4S/m-p/652362#M110754</link>
      <description>&lt;P&gt;I also add a tcpdump taken from the SC4S, I forced pings and curls to 443, those seem to work.&lt;/P&gt;&lt;P&gt;all the other lines are the attempts to connect to 8088 , called radan-http (?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 11:53:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-events-ingested-via-HEC-from-Syslog-Connector-for-Splunk-SC4S/m-p/652362#M110754</guid>
      <dc:creator>corti77</dc:creator>
      <dc:date>2023-07-28T11:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: No events ingested via HEC from Syslog Connector for Splunk (SC4S)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-events-ingested-via-HEC-from-Syslog-Connector-for-Splunk-SC4S/m-p/652364#M110755</link>
      <description>&lt;P&gt;I attach the pcap from the splunk server. Clearly, they don't manage to establish the TCP handshake but I don't understand why... if there are no firewall rules involved, everything points to Splunk misconfiguration but I cannot see where.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 12:07:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-events-ingested-via-HEC-from-Syslog-Connector-for-Splunk-SC4S/m-p/652364#M110755</guid>
      <dc:creator>corti77</dc:creator>
      <dc:date>2023-07-28T12:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: No events ingested via HEC from Syslog Connector for Splunk (SC4S)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-events-ingested-via-HEC-from-Syslog-Connector-for-Splunk-SC4S/m-p/652370#M110756</link>
      <description>&lt;P&gt;this is the output&amp;nbsp; from the SC4S container. I created a new token to be sure, still the same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/sc4s$ docker logs SC4S&lt;BR /&gt;curl: (7) Failed to connect to splunk.xx.yy port 8088: Connection timed out&lt;BR /&gt;SC4S_ENV_CHECK_HEC: Invalid Splunk HEC URL, invalid token, or other HEC connectivity issue index=main. sourcetype=sc4s:fallback&lt;BR /&gt;Startup will continue to prevent data loss if this is a transient failure.&lt;/P&gt;&lt;P&gt;syslog-ng checking config&lt;BR /&gt;sc4s version=1.110.1&lt;BR /&gt;sc4s versions &amp;lt;2.0.0 are depreated please review and follow upgrade docs&lt;BR /&gt;starting goss&lt;BR /&gt;starting syslog-ng&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 13:19:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-events-ingested-via-HEC-from-Syslog-Connector-for-Splunk-SC4S/m-p/652370#M110756</guid>
      <dc:creator>corti77</dc:creator>
      <dc:date>2023-07-28T13:19:51Z</dc:date>
    </item>
  </channel>
</rss>

