<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure different sourcetypes for udp port 514 ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165782#M33625</link>
    <description>&lt;P&gt;Why when I restrict host I don't receive anything?There is some specific configuration?&lt;BR /&gt;
My firewall and my switch are allow to send logs.&lt;/P&gt;</description>
    <pubDate>Mon, 01 Feb 2016 18:43:53 GMT</pubDate>
    <dc:creator>tiagomiranda</dc:creator>
    <dc:date>2016-02-01T18:43:53Z</dc:date>
    <item>
      <title>How to configure different sourcetypes for udp port 514 ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165772#M33615</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have configured two network devices (cisco router and fortigate firewall) to send logs to Splunk server via udp port 514 .I can successfully see all the raw logs but particular apps wont show any data because the sourcetype doesnt match.I cant define different sourcetypes to same udp port in "data inputs".How can I overcome this issue ?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Dec 2014 10:52:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165772#M33615</guid>
      <dc:creator>aeshan</dc:creator>
      <dc:date>2014-12-29T10:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure different sourcetypes for udp port 514 ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165773#M33616</link>
      <description>&lt;P&gt;You can use the following in your inputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[udp://123.456.789:514]
index = networking
sourcetype = cisco

[udp://123.456.890:514]
index = networking
sourcetype = fortinet
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 29 Dec 2014 14:56:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165773#M33616</guid>
      <dc:creator>treinke</dc:creator>
      <dc:date>2014-12-29T14:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure different sourcetypes for udp port 514 ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165774#M33617</link>
      <description>&lt;P&gt;Thank you very much for the solution.Can you please specify which inputs.conf file I should edited.I saw there several inputs.conf files in several folders.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2014 04:36:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165774#M33617</guid>
      <dc:creator>aeshan</dc:creator>
      <dc:date>2014-12-31T04:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure different sourcetypes for udp port 514 ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165775#M33618</link>
      <description>&lt;P&gt;whats your splunk topology and source paths? &lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2014 04:49:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165775#M33618</guid>
      <dc:creator>jayannah</dc:creator>
      <dc:date>2014-12-31T04:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure different sourcetypes for udp port 514 ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165776#M33619</link>
      <description>&lt;P&gt;you can edit in local directory of app name folder&lt;BR /&gt;
$SPLUNK_HOME/etc/apps/app-name/local/inputs.conf&lt;BR /&gt;
or you can directly modify from splunk web &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/Enableareceiver"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/Enableareceiver&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2014 04:53:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165776#M33619</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2014-12-31T04:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure different sourcetypes for udp port 514 ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165777#M33620</link>
      <description>&lt;P&gt;When you configure the inputs from the website, the inputs.conf file will be in the app folder that you were in before you when in to the inputs section.  For example if you were in the Search &amp;amp; Reporting app, current location for your inputs.conf would be in &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME/etc/apps/search/local/inputs.conf
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you are not sure where to store your file with these stanzas, you can use&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME/etc/system/local/inputs.conf
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 31 Dec 2014 05:24:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165777#M33620</guid>
      <dc:creator>treinke</dc:creator>
      <dc:date>2014-12-31T05:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure different sourcetypes for udp port 514 ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165778#M33621</link>
      <description>&lt;P&gt;Hi @aeshan&lt;/P&gt;

&lt;P&gt;Did Anthony Reinke's or @kml_uvce's answers below solve your question? If yes, please accept the one that did to resolve this post by clicking "Accept" right below the appropriate answer. Thanks!&lt;/P&gt;

&lt;P&gt;Patrick&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 02:45:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165778#M33621</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2015-01-07T02:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure different sourcetypes for udp port 514 ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165779#M33622</link>
      <description>&lt;P&gt;Hi..&lt;/P&gt;

&lt;P&gt;Edit the inputs.conf file in $SPLUNK_HOME/etc/apps/app-name/local/inputs.conf or  $SPLUNK_HOME/etc/system/local/inputs.conf or $SPLUNK_HOME/etc/apps/search/local/inputs.conf &lt;BR /&gt;
Note :  no need to edit and enter the below configuration in all the input file. any one of the file is fine&lt;/P&gt;

&lt;P&gt;[udp://ipaddressofthedevice:514]&lt;BR /&gt;
 index = linux&lt;BR /&gt;
 sourcetype = linuxevents&lt;/P&gt;

&lt;P&gt;[udp://ipaddressofthdevice:514]&lt;BR /&gt;
 index = linux&lt;BR /&gt;
 sourcetype = syslog&lt;/P&gt;

&lt;P&gt;Ex : &lt;BR /&gt;
[udp://10.1.1.10:514]&lt;BR /&gt;
 index = linux&lt;BR /&gt;
 sourcetype = linuxevents&lt;/P&gt;

&lt;P&gt;[udp://192.168.1.9:514]&lt;BR /&gt;
 index = linux&lt;BR /&gt;
 sourcetype = syslog&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:34:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165779#M33622</guid>
      <dc:creator>82padarthi</dc:creator>
      <dc:date>2020-09-28T18:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure different sourcetypes for udp port 514 ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165780#M33623</link>
      <description>&lt;P&gt;Up to the config, you cannot define more than one input for the same port: &lt;BR /&gt;
    [udp://&lt;REMOTE server=""&gt;:&lt;PORT&gt;]&lt;BR /&gt;
    * Similar to TCP, except that it listens on a UDP port.&lt;BR /&gt;
    * Only one stanza per port number is currently supported.&lt;/PORT&gt;&lt;/REMOTE&gt;&lt;/P&gt;

&lt;P&gt;However, did it work for any of you?? &lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 23:05:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165780#M33623</guid>
      <dc:creator>jdanij</dc:creator>
      <dc:date>2015-10-19T23:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure different sourcetypes for udp port 514 ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165781#M33624</link>
      <description>&lt;P&gt;you are adding an ip address to limit the input selection.  if you added  &lt;CODE&gt;[udp://514]&lt;/CODE&gt; to the inputs.conf file, you are saying any ip address on UDP port 514.  This is really more like  &lt;CODE&gt;[udp://*:514]&lt;/CODE&gt; .  When you add the ip address in to the stanza, you are narrowing down the parameters.  So &lt;CODE&gt;[udp://123.456.789:514]&lt;/CODE&gt; is saying from this ip on this port, do the following the in the stanza.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2015 20:23:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165781#M33624</guid>
      <dc:creator>treinke</dc:creator>
      <dc:date>2015-10-21T20:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure different sourcetypes for udp port 514 ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165782#M33625</link>
      <description>&lt;P&gt;Why when I restrict host I don't receive anything?There is some specific configuration?&lt;BR /&gt;
My firewall and my switch are allow to send logs.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2016 18:43:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165782#M33625</guid>
      <dc:creator>tiagomiranda</dc:creator>
      <dc:date>2016-02-01T18:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure different sourcetypes for udp port 514 ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165783#M33626</link>
      <description>&lt;P&gt;are you seeing the packets with tcpdump/wireshark on the Splunk server?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2016 18:51:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/165783#M33626</guid>
      <dc:creator>treinke</dc:creator>
      <dc:date>2016-02-01T18:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure different sourcetypes for udp port 514 ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/638636#M109049</link>
      <description>&lt;P&gt;This exactly as stated here, totally worked for us (Splunk 9)&lt;BR /&gt;Create the inputs.con file, add stanza as indicated here, no more no less and save the file. In Config Explorer do a debug/refresh and you will see these special inputs appear in the GUI as "[IP]:[PORT]" and data will trickle in to the specified index(es) using the specified sourcetype.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 11:14:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-different-sourcetypes-for-udp-port-514/m-p/638636#M109049</guid>
      <dc:creator>amnonh</dc:creator>
      <dc:date>2023-04-04T11:14:02Z</dc:date>
    </item>
  </channel>
</rss>

