<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cymphonix Network Composer Logging Issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Cymphonix-Network-Composer-Logging-Issue/m-p/86142#M17917</link>
    <description>&lt;P&gt;Verified inbound rule in Windows Firewall allowing UDP Port 521 (although firewall is off).&lt;/P&gt;

&lt;P&gt;WireShark capture shows no UDP packets coming from the Cymphonix IP to the Splunk IP.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Mar 2012 23:15:31 GMT</pubDate>
    <dc:creator>afields</dc:creator>
    <dc:date>2012-03-06T23:15:31Z</dc:date>
    <item>
      <title>Cymphonix Network Composer Logging Issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cymphonix-Network-Composer-Logging-Issue/m-p/86140#M17915</link>
      <description>&lt;P&gt;We are running &lt;STRONG&gt;Splunk for Windows 4.3&lt;/STRONG&gt; on Windows Server 2008 R2 x64.  We are trying to &lt;STRONG&gt;pull Syslog data&lt;/STRONG&gt; from a Cymphonix Network Composer EX350 unit (software version 9.2.4), &lt;STRONG&gt;via UDP port 521&lt;/STRONG&gt; (514 is in use by a WatchGuard Firewall unit).&lt;/P&gt;

&lt;P&gt;The Cymphonix unit is pointing to the correct IP address for the Splunk server, and a &lt;STRONG&gt;Data Input&lt;/STRONG&gt; on the Splunk server is configured to &lt;STRONG&gt;listen on UDP port 521&lt;/STRONG&gt;.  However, we are receiving &lt;STRONG&gt;no events/data&lt;/STRONG&gt; from that Data Input.&lt;/P&gt;

&lt;P&gt;I realize that this may very well be a Cymphonix issue, not a Splunk one, however I would like to cover all my bases here.  &lt;STRONG&gt;Has anyone had experiencing configuring Splunk to work with a Cymphonix unit (or other such UDP unit)?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2012 22:30:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cymphonix-Network-Composer-Logging-Issue/m-p/86140#M17915</guid>
      <dc:creator>afields</dc:creator>
      <dc:date>2012-03-06T22:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cymphonix Network Composer Logging Issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cymphonix-Network-Composer-Logging-Issue/m-p/86141#M17916</link>
      <description>&lt;P&gt;Make sure port 521/udp is open on your Win64 host firewall.  If not, it'll obviously be blocked and you'll never see it.  Then, check with a sniffer ( &lt;A href="http://www.wireshark.org"&gt;http://www.wireshark.org&lt;/A&gt; ) to see the packets coming through.  Note:  Typically, wireshark will see/sniff packets before the firewall gets to filter them, which is why I suggested to check the firewall first.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2012 22:50:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cymphonix-Network-Composer-Logging-Issue/m-p/86141#M17916</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2012-03-06T22:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cymphonix Network Composer Logging Issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cymphonix-Network-Composer-Logging-Issue/m-p/86142#M17917</link>
      <description>&lt;P&gt;Verified inbound rule in Windows Firewall allowing UDP Port 521 (although firewall is off).&lt;/P&gt;

&lt;P&gt;WireShark capture shows no UDP packets coming from the Cymphonix IP to the Splunk IP.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2012 23:15:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cymphonix-Network-Composer-Logging-Issue/m-p/86142#M17917</guid>
      <dc:creator>afields</dc:creator>
      <dc:date>2012-03-06T23:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cymphonix Network Composer Logging Issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cymphonix-Network-Composer-Logging-Issue/m-p/86143#M17918</link>
      <description>&lt;P&gt;Then, arguably ... either the Cymphonix &lt;STRONG&gt;isn't&lt;/STRONG&gt; sending data on that port, or it's getting lost somewhere on the network between the two.  It's hard for Splunk to index that which the network adapter never receives.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2012 04:28:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cymphonix-Network-Composer-Logging-Issue/m-p/86143#M17918</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2012-03-07T04:28:54Z</dc:date>
    </item>
  </channel>
</rss>

