<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Connect For Syslog - Sending syslog using Kiwi Syslog Message Generator (UDP 514) failed but TCP 514 success in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Connect-For-Syslog-Sending-syslog-using-Kiwi-Syslog/m-p/686608#M114473</link>
    <description>&lt;P&gt;First and foremost - verify if:&lt;/P&gt;&lt;P&gt;1) The events are generated at the source machine at all - run a wireshark there and see if the packets appear on the wire. If not - here's your culprit - troubleshoot your Kiwi.&lt;/P&gt;&lt;P&gt;2) If they are being sent, check with tcpdump on the receiving end.&lt;/P&gt;&lt;P&gt;3) If you can see the packets on the wire, check firewall rules and rp_filter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 06 May 2024 17:33:55 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-05-06T17:33:55Z</dc:date>
    <item>
      <title>Splunk Connect For Syslog - Sending syslog using Kiwi Syslog Message Generator (UDP 514) failed but TCP 514 success</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Connect-For-Syslog-Sending-syslog-using-Kiwi-Syslog/m-p/686592#M114471</link>
      <description>&lt;P&gt;Hello. I am completely new at Splunk. Recently,&amp;nbsp;I've recently taken on a role where I'll be working with Splunk quite a lot. I have a question about SC4S (Splunk Connect For Syslog). I successfully installed the SC4S (podman + systemd) using the guide from this:&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunk.github.io/splunk-connect-for-syslog/main/gettingstarted/podman-systemd-general/" target="_blank" rel="noopener"&gt;https://splunk.github.io/splunk-connect-for-syslog/main/gettingstarted/podman-systemd-general/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The SC4S is installed in Centos 7 VM (in vsphere). The HEC is configured successfully in heavy forwarder and I can successfully see the SC4S is properly communicating with Splunk.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="azer271_0-1715008046922.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30702i6F0AE501053E71FA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="azer271_0-1715008046922.png" alt="azer271_0-1715008046922.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;After that, I used Kiwi Syslog Message Generator from my windows 10 machine to send a syslog tcp message to the Centos 7 VM.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="azer271_1-1715008106499.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30703i006BF574F631DD4C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="azer271_1-1715008106499.png" alt="azer271_1-1715008106499.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Successful Output (TCP):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="azer271_2-1715008125518.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30704iE9258271CF1E40FE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="azer271_2-1715008125518.png" alt="azer271_2-1715008125518.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, if i sent a&amp;nbsp;syslog udp message, the message was not successfully sent. As shown in the screenshot, the messages sent was zero after i pressed send.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="azer271_3-1715008305699.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30705i3F8A30E26194A0E5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="azer271_3-1715008305699.png" alt="azer271_3-1715008305699.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Unsuccessful Output (UDP):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="azer271_4-1715008356739.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30707i92BB1E67730EC92C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="azer271_4-1715008356739.png" alt="azer271_4-1715008356739.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;No new messages were shown in Splunk Web.&lt;/P&gt;&lt;P&gt;514 TCP and UDP is enabled in the firewall in Centos 7. I would like to request assistance about this issue.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 06 May 2024 15:22:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Connect-For-Syslog-Sending-syslog-using-Kiwi-Syslog/m-p/686592#M114471</guid>
      <dc:creator>azer271</dc:creator>
      <dc:date>2024-05-06T15:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Connect For Syslog - Sending syslog using Kiwi Syslog Message Generator (UDP 514) failed but TCP 514 success</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Connect-For-Syslog-Sending-syslog-using-Kiwi-Syslog/m-p/686603#M114472</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I've never used Kiwi syslog, but you can use the netcat (nc) utility to send test syslog messages to the SC4S server first and check, netcat needs to be installed. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;UDP test &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;echo "My Test UDP syslog message" | nc -w1 -u &amp;lt;YOUR SC4S Server&amp;gt; 514 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OR locally from the SC4S server &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;echo "My Test UDP syslog message" | nc -w1 -u localhost 514&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And see if any messages are sent to the Splunk/HEC&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also check SC4S to see if data is being sent, when you send data from the Kiwi system&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;sudo tcpdump -i any udp port 514&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Other things to check: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Check the /opt/sc4s/env_file - these are the default ports, but I can't remember if you need to add these as they should be default, may be worth adding these and restarting and see if that could be the cause.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SC4S_LISTEN_DEFAULT_TCP_PORT=514&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SC4S_LISTEN_DEFAULT_UDP_PORT=514&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Check the logs&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;podman logs SC4S&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;You said the firewall is ok but might be worth disabling it temporarily.&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 16:21:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Connect-For-Syslog-Sending-syslog-using-Kiwi-Syslog/m-p/686603#M114472</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2024-05-06T16:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Connect For Syslog - Sending syslog using Kiwi Syslog Message Generator (UDP 514) failed but TCP 514 success</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Connect-For-Syslog-Sending-syslog-using-Kiwi-Syslog/m-p/686608#M114473</link>
      <description>&lt;P&gt;First and foremost - verify if:&lt;/P&gt;&lt;P&gt;1) The events are generated at the source machine at all - run a wireshark there and see if the packets appear on the wire. If not - here's your culprit - troubleshoot your Kiwi.&lt;/P&gt;&lt;P&gt;2) If they are being sent, check with tcpdump on the receiving end.&lt;/P&gt;&lt;P&gt;3) If you can see the packets on the wire, check firewall rules and rp_filter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2024 17:33:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Connect-For-Syslog-Sending-syslog-using-Kiwi-Syslog/m-p/686608#M114473</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-05-06T17:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Connect For Syslog - Sending syslog using Kiwi Syslog Message Generator (UDP 514) failed but TCP 514 success</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Connect-For-Syslog-Sending-syslog-using-Kiwi-Syslog/m-p/686636#M114478</link>
      <description>&lt;P&gt;I checked with tcpdump and wireshark. I can clearly see the TCP packets, but not the UDP packets. However, I can see the traffic by echoing the message (TCP and UDP as well) to SC4S server. I believe its the issue of the Kiwi Syslog Message Generator.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks guys.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2024 02:25:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Connect-For-Syslog-Sending-syslog-using-Kiwi-Syslog/m-p/686636#M114478</guid>
      <dc:creator>azer271</dc:creator>
      <dc:date>2024-05-07T02:25:32Z</dc:date>
    </item>
  </channel>
</rss>

