<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Running rsyslog and Splunk Enterprise on the same machine in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Running-rsyslog-and-Splunk-Enterprise-on-the-same-machine/m-p/744733#M118358</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;thanks for your response. Yes, it's configured properly but tcpdump showed nothing coming to port 514. It seems the problem might be on the UCS side. As someone on the Cisco community suggested, tried to run on UCS side "&lt;STRONG&gt;ethanalyzer local interface mgmt capture-filter "port 514" limit-captured-frames 0 detail&lt;/STRONG&gt;" but looks like it's not generating any traffic to send out port 514 on UCS itself and hence no data on the rsyso&lt;/P&gt;</description>
    <pubDate>Wed, 23 Apr 2025 02:08:46 GMT</pubDate>
    <dc:creator>jkamdar</dc:creator>
    <dc:date>2025-04-23T02:08:46Z</dc:date>
    <item>
      <title>Running rsyslog and Splunk Enterprise on the same machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Running-rsyslog-and-Splunk-Enterprise-on-the-same-machine/m-p/744712#M118351</link>
      <description>&lt;P&gt;Hi, I have a small lab (air gapped) with about 2 Linux servers&amp;nbsp; not including the Splunk server and 25 Windows machine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have deployed Splunk and ingesting logs from all Linux and Windows clients and also from network switch, VMWare server and hosts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am able to send logs from network switch and VMWare hosts directly into Splunk using using "Data Inputs-&amp;gt;TCP" and by picking different ports for each service but for Cisco UCS Chassis, to send logs, I can't configure other than syslog server name and log level.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I setup a rsyslog server on the same machine as Splunk Enterprise. It seems to be running but I don't logs from Cisco UCS. I have check firewall rules as well and all seems to be configured properly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any tips about running rsyslog and Splunk server on the same machine and about sending Cisco UCS logs to rsyslog/splunk would be appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, I can't provide much info as this is an air gapped lab.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 18:48:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Running-rsyslog-and-Splunk-Enterprise-on-the-same-machine/m-p/744712#M118351</guid>
      <dc:creator>jkamdar</dc:creator>
      <dc:date>2025-04-22T18:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: Running rsyslog and Splunk Enterprise on the same machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Running-rsyslog-and-Splunk-Enterprise-on-the-same-machine/m-p/744721#M118355</link>
      <description>&lt;P&gt;There is absolutely no problem with running rsyslog on the same box as splunk provided that you're not trying to bind the same port(s) to both programs.&lt;/P&gt;&lt;P&gt;Have you configured rsyslog to receive network data on proper ports? Did you verify it is listening? Did you check with tcpdump/wireshark whether UCS is sending data?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 20:37:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Running-rsyslog-and-Splunk-Enterprise-on-the-same-machine/m-p/744721#M118355</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-04-22T20:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: Running rsyslog and Splunk Enterprise on the same machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Running-rsyslog-and-Splunk-Enterprise-on-the-same-machine/m-p/744733#M118358</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;thanks for your response. Yes, it's configured properly but tcpdump showed nothing coming to port 514. It seems the problem might be on the UCS side. As someone on the Cisco community suggested, tried to run on UCS side "&lt;STRONG&gt;ethanalyzer local interface mgmt capture-filter "port 514" limit-captured-frames 0 detail&lt;/STRONG&gt;" but looks like it's not generating any traffic to send out port 514 on UCS itself and hence no data on the rsyso&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2025 02:08:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Running-rsyslog-and-Splunk-Enterprise-on-the-same-machine/m-p/744733#M118358</guid>
      <dc:creator>jkamdar</dc:creator>
      <dc:date>2025-04-23T02:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: Running rsyslog and Splunk Enterprise on the same machine</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Running-rsyslog-and-Splunk-Enterprise-on-the-same-machine/m-p/745008#M118430</link>
      <description>&lt;P&gt;Just wanted to report, the problem has been solved. Everything remained same, I just restarted rsyslog and I started seeing logs on the rsyslog server; when in doubt, reboot seemed to have worked here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2025 14:49:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Running-rsyslog-and-Splunk-Enterprise-on-the-same-machine/m-p/745008#M118430</guid>
      <dc:creator>jkamdar</dc:creator>
      <dc:date>2025-04-25T14:49:56Z</dc:date>
    </item>
  </channel>
</rss>

