<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Only one syslog shows up on server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Only-one-syslog-shows-up-on-server/m-p/132741#M27265</link>
    <description>&lt;P&gt;The splunk server is on subnet 192.168.30.x&lt;BR /&gt;
I added a pfsense at 192.168.30.254 and the logs show up&lt;BR /&gt;
I try to add a dell switch from 192.168.30.1 and it does not show up&lt;BR /&gt;
I try to add a pfsense from 192.168.20.254 and it doesn't show up (I assume I need a forwarder for this one?)&lt;/P&gt;</description>
    <pubDate>Thu, 07 Nov 2013 19:39:32 GMT</pubDate>
    <dc:creator>slacknetter</dc:creator>
    <dc:date>2013-11-07T19:39:32Z</dc:date>
    <item>
      <title>Only one syslog shows up on server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Only-one-syslog-shows-up-on-server/m-p/132739#M27263</link>
      <description>&lt;P&gt;I have a new windows install and I can only get one syslog to show up.  Any other devices I direct to send their logs do not show up.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2013 15:42:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Only-one-syslog-shows-up-on-server/m-p/132739#M27263</guid>
      <dc:creator>slacknetter</dc:creator>
      <dc:date>2013-11-07T15:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: Only one syslog shows up on server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Only-one-syslog-shows-up-on-server/m-p/132740#M27264</link>
      <description>&lt;P&gt;Can you elaborate? It is unclear with what you need help.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2013 19:35:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Only-one-syslog-shows-up-on-server/m-p/132740#M27264</guid>
      <dc:creator>jtrucks</dc:creator>
      <dc:date>2013-11-07T19:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: Only one syslog shows up on server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Only-one-syslog-shows-up-on-server/m-p/132741#M27265</link>
      <description>&lt;P&gt;The splunk server is on subnet 192.168.30.x&lt;BR /&gt;
I added a pfsense at 192.168.30.254 and the logs show up&lt;BR /&gt;
I try to add a dell switch from 192.168.30.1 and it does not show up&lt;BR /&gt;
I try to add a pfsense from 192.168.20.254 and it doesn't show up (I assume I need a forwarder for this one?)&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2013 19:39:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Only-one-syslog-shows-up-on-server/m-p/132741#M27265</guid>
      <dc:creator>slacknetter</dc:creator>
      <dc:date>2013-11-07T19:39:32Z</dc:date>
    </item>
    <item>
      <title>Re: Only one syslog shows up on server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Only-one-syslog-shows-up-on-server/m-p/132742#M27266</link>
      <description>&lt;P&gt;How have you configured your settings? If you are doing it via a data stream, then there are three things that need to be done for it to work.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;The syslog servers need to be configured to send data to a specific port on the Splunk machine e.g. TCP/5000&lt;/LI&gt;
&lt;LI&gt;The splunk server needs to be configured to read that port and index the data. This can be found under inputs.&lt;/LI&gt;
&lt;LI&gt;The firewalls between the machines must be configured to allow that data to flow through the TCP/UDP ports. This includes the local windows firewall too. &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;A quick google search for any of these things will give you the information you need to do that. &lt;/P&gt;

&lt;P&gt;Similiar principles apply if you're using a forwarder.. except in step 1, the forwarder reads the syslog and forwards it instead of the machine directly sending it out as a syslog stream.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2013 21:06:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Only-one-syslog-shows-up-on-server/m-p/132742#M27266</guid>
      <dc:creator>yong_ly</dc:creator>
      <dc:date>2013-11-07T21:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: Only one syslog shows up on server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Only-one-syslog-shows-up-on-server/m-p/132743#M27267</link>
      <description>&lt;P&gt;I have setup a UDP syslog on port 514 on the splunk server and it is receiving data on that port from one device.&lt;BR /&gt;
the second device is on the same subnet and it is still not showing up&lt;BR /&gt;
the 3rd device is on the other side of a vpn and all ports and traffic UDP and TCP are allowed. all of my other services on all other devices and servers do not have any issues connecting over this link&lt;BR /&gt;
firewall on the splunk server is off and there are also rules allowing all connections to udp port 514&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2013 21:13:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Only-one-syslog-shows-up-on-server/m-p/132743#M27267</guid>
      <dc:creator>slacknetter</dc:creator>
      <dc:date>2013-11-07T21:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: Only one syslog shows up on server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Only-one-syslog-shows-up-on-server/m-p/132744#M27268</link>
      <description>&lt;P&gt;Are your routing tables on the devices generating the syslogs identical?&lt;/P&gt;

&lt;P&gt;(PS: If you are using the native Splunk syslog server then you are not using syslog-ng.)&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2013 21:26:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Only-one-syslog-shows-up-on-server/m-p/132744#M27268</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2013-11-07T21:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Only one syslog shows up on server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Only-one-syslog-shows-up-on-server/m-p/132745#M27269</link>
      <description>&lt;P&gt;I assume you've done a trace on both ends to make sure that the syslog data is being sent from the originating servers and being received on the splunk instance?? &lt;/P&gt;

&lt;P&gt;Is there another syslog daemon running on your splunk instance or another application using that port? If so then it's possible the syslogs coming int your machine are being aggregated into the local syslog..&lt;/P&gt;

&lt;P&gt;I would suggest doing a netstat to make sure there's no other applications using that. Or changing to a different port above 1024..&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2013 21:31:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Only-one-syslog-shows-up-on-server/m-p/132745#M27269</guid>
      <dc:creator>yong_ly</dc:creator>
      <dc:date>2013-11-07T21:31:51Z</dc:date>
    </item>
  </channel>
</rss>

