<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: syslog is not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/syslog-is-not-working/m-p/24634#M3909</link>
    <description>&lt;P&gt;Is that really the correct syntax on your Cisco device? Shouldn't it be "logging host 192.168.1.7"?&lt;/P&gt;</description>
    <pubDate>Wed, 08 May 2013 20:08:15 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2013-05-08T20:08:15Z</dc:date>
    <item>
      <title>syslog is not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-is-not-working/m-p/24629#M3904</link>
      <description>&lt;P&gt;I configure syslog on my cisco router and switch, and I am no receiving any data into my splunk server. Yes I enable syslog on my devices and i enable port 514 on splunk server&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Sun, 05 May 2013 17:05:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-is-not-working/m-p/24629#M3904</guid>
      <dc:creator>carcab</dc:creator>
      <dc:date>2013-05-05T17:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: syslog is not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-is-not-working/m-p/24630#M3905</link>
      <description>&lt;P&gt;Did you enable TCP or UDP in the Splunk configuration? What level of logging did you choose for your cisco devices? what OS are you using for your splunk server? &lt;/P&gt;</description>
      <pubDate>Sun, 05 May 2013 17:55:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-is-not-working/m-p/24630#M3905</guid>
      <dc:creator>Voltaire</dc:creator>
      <dc:date>2013-05-05T17:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: syslog is not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-is-not-working/m-p/24631#M3906</link>
      <description>&lt;P&gt;Except Splunk is running as root/privileged user (not recommended), It would not listen on ports below 1024. Syslog uses UDP 514. You could also have your iptables redirect port 514 to a higher port which splunk can listen on.&lt;/P&gt;</description>
      <pubDate>Sun, 05 May 2013 23:43:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-is-not-working/m-p/24631#M3906</guid>
      <dc:creator>seunomosowon</dc:creator>
      <dc:date>2013-05-05T23:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: syslog is not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-is-not-working/m-p/24632#M3907</link>
      <description>&lt;P&gt;Maybe a kernel security, Did you checked this answer ?&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/answers/12876/splunk-running-on-my-linux-server-is-only-showing-me-events-from-my-local-subnet-what-is-going-on"&gt;http://splunk-base.splunk.com/answers/12876/splunk-running-on-my-linux-server-is-only-showing-me-events-from-my-local-subnet-what-is-going-on&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2013 06:58:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-is-not-working/m-p/24632#M3907</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-05-06T06:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: syslog is not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-is-not-working/m-p/24633#M3908</link>
      <description>&lt;P&gt;I think the problem that I have is on my cisco devices configuration. If anyone can help me with this configuration, I will thank you. &lt;/P&gt;

&lt;P&gt;I am using windows 7 for Splunk server.&lt;/P&gt;

&lt;P&gt;I enable TCP and  UDP in the Splunk configuration.&lt;/P&gt;

&lt;P&gt;On my cisco devices I configure them with this commands: #logging 192.168.1.7 this address is splunk server. &lt;/P&gt;

&lt;P&gt;On Splunk server:  - Data Inputs UDP ( Listen on a UDP port for incoming data, e.g. syslog). &lt;BR /&gt;
                                 -New&lt;BR /&gt;
                                 -UDP port 514&lt;BR /&gt;
                                 -Set source type: From list&lt;BR /&gt;
                                 -Select source type from list: Syslog&lt;BR /&gt;
                                 -Save.&lt;BR /&gt;
-What level of logging did you choose for your cisco devices?  How to change the level of logging for you cisco device?&lt;BR /&gt;
-Except Splunk is running as root/privileged ?  How to run splunk as a root or privileged?&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2013 19:54:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-is-not-working/m-p/24633#M3908</guid>
      <dc:creator>carcab</dc:creator>
      <dc:date>2013-05-08T19:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: syslog is not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/syslog-is-not-working/m-p/24634#M3909</link>
      <description>&lt;P&gt;Is that really the correct syntax on your Cisco device? Shouldn't it be "logging host 192.168.1.7"?&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2013 20:08:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/syslog-is-not-working/m-p/24634#M3909</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-05-08T20:08:15Z</dc:date>
    </item>
  </channel>
</rss>

