<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VM Splunk / Proxmox / Unifi in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/VM-Splunk-Proxmox-Unifi/m-p/689282#M114727</link>
    <description>&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;Hello,&lt;BR /&gt;I would like my router/firewall Unifi UDM-SE send his logs to my VM (splunk+ubuntu server).&lt;BR /&gt;What I have done:&lt;BR /&gt;&lt;BR /&gt;- on the proxmox VM no FW (during the test)&lt;BR /&gt;- on my VM I have two NICs, one for the management (network 205) and one for the remote logging location (splunk - network 203 -same as my udm network).&lt;BR /&gt;- on my VM, ufw is running, I have opened port 9997 and port 514 .&lt;BR /&gt;- on my UDM SE, I have forwarded the syslog to my remote splunk server (network 203).&lt;BR /&gt;&lt;BR /&gt;On the Splunk server, port 514 and 9997 are listening.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Until now, no logs appear on my Splunk.&lt;BR /&gt;How "ufw" is dealing when running two different networks ?&lt;/DIV&gt;&lt;DIV class=""&gt;How to add the second NIC (network 203) to Splunk ?&lt;BR /&gt;&lt;BR /&gt;Ideas ?&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Sat, 01 Jun 2024 08:08:25 GMT</pubDate>
    <dc:creator>splunkman-70</dc:creator>
    <dc:date>2024-06-01T08:08:25Z</dc:date>
    <item>
      <title>VM Splunk / Proxmox / Unifi</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/VM-Splunk-Proxmox-Unifi/m-p/689282#M114727</link>
      <description>&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;Hello,&lt;BR /&gt;I would like my router/firewall Unifi UDM-SE send his logs to my VM (splunk+ubuntu server).&lt;BR /&gt;What I have done:&lt;BR /&gt;&lt;BR /&gt;- on the proxmox VM no FW (during the test)&lt;BR /&gt;- on my VM I have two NICs, one for the management (network 205) and one for the remote logging location (splunk - network 203 -same as my udm network).&lt;BR /&gt;- on my VM, ufw is running, I have opened port 9997 and port 514 .&lt;BR /&gt;- on my UDM SE, I have forwarded the syslog to my remote splunk server (network 203).&lt;BR /&gt;&lt;BR /&gt;On the Splunk server, port 514 and 9997 are listening.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Until now, no logs appear on my Splunk.&lt;BR /&gt;How "ufw" is dealing when running two different networks ?&lt;/DIV&gt;&lt;DIV class=""&gt;How to add the second NIC (network 203) to Splunk ?&lt;BR /&gt;&lt;BR /&gt;Ideas ?&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 01 Jun 2024 08:08:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/VM-Splunk-Proxmox-Unifi/m-p/689282#M114727</guid>
      <dc:creator>splunkman-70</dc:creator>
      <dc:date>2024-06-01T08:08:25Z</dc:date>
    </item>
  </channel>
</rss>

