<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Should each device sending data have a different UDP input port? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Should-each-device-sending-data-have-a-different-UDP-input-port/m-p/295135#M56067</link>
    <description>&lt;P&gt;Hi julianosantos,&lt;/P&gt;

&lt;P&gt;Welcome to Splunk &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;To keep it simple: I would use a different port for each device. This way you can configure the sourcetypes in the Splunk UI.&lt;/P&gt;

&lt;P&gt;If some devices cannot send data to other ports than 514 you can use this approach &lt;A href="https://answers.splunk.com/answers/438083/how-to-change-syslog-host-to-a-specific-sourcetype-1.html"&gt;https://answers.splunk.com/answers/438083/how-to-change-syslog-host-to-a-specific-sourcetype-1.html&lt;/A&gt; or this one &lt;A href="https://answers.splunk.com/answers/369375/how-do-i-set-different-source-types-on-one-data-in-1.html"&gt;https://answers.splunk.com/answers/369375/how-do-i-set-different-source-types-on-one-data-in-1.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jul 2017 21:14:33 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2017-07-04T21:14:33Z</dc:date>
    <item>
      <title>Should each device sending data have a different UDP input port?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Should-each-device-sending-data-have-a-different-UDP-input-port/m-p/295134#M56066</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;
I'm new and this is my first post here in the community.&lt;/P&gt;

&lt;P&gt;I did the Splunk installation with the purpose of testing for enterprise deployment.&lt;BR /&gt;
We have several devices like Palo Alto, Juniper, Trend Micro and etc.&lt;BR /&gt;
My question is as follows.&lt;BR /&gt;
I created a UDP Input Data on port 514 for my Palo Alto device. I noticed that others also work on the same door.&lt;BR /&gt;
When creating a new UDP Input Data with the same port, but with different source type, I can not.&lt;BR /&gt;
Does each device have to be configured on a different port?&lt;BR /&gt;
What is the recommendation? Following for each device a different port?&lt;/P&gt;

&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jul 2017 20:20:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Should-each-device-sending-data-have-a-different-UDP-input-port/m-p/295134#M56066</guid>
      <dc:creator>julianosantos</dc:creator>
      <dc:date>2017-07-04T20:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: Should each device sending data have a different UDP input port?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Should-each-device-sending-data-have-a-different-UDP-input-port/m-p/295135#M56067</link>
      <description>&lt;P&gt;Hi julianosantos,&lt;/P&gt;

&lt;P&gt;Welcome to Splunk &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;To keep it simple: I would use a different port for each device. This way you can configure the sourcetypes in the Splunk UI.&lt;/P&gt;

&lt;P&gt;If some devices cannot send data to other ports than 514 you can use this approach &lt;A href="https://answers.splunk.com/answers/438083/how-to-change-syslog-host-to-a-specific-sourcetype-1.html"&gt;https://answers.splunk.com/answers/438083/how-to-change-syslog-host-to-a-specific-sourcetype-1.html&lt;/A&gt; or this one &lt;A href="https://answers.splunk.com/answers/369375/how-do-i-set-different-source-types-on-one-data-in-1.html"&gt;https://answers.splunk.com/answers/369375/how-do-i-set-different-source-types-on-one-data-in-1.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jul 2017 21:14:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Should-each-device-sending-data-have-a-different-UDP-input-port/m-p/295135#M56067</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2017-07-04T21:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: Should each device sending data have a different UDP input port?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Should-each-device-sending-data-have-a-different-UDP-input-port/m-p/295136#M56068</link>
      <description>&lt;P&gt;Use a different port for each device.  You can use an IP filter in most syslog servers but it means that you have to constantly update this which is a MAJOR hassle.  Also read this:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.georgestarcher.com/splunk-success-with-syslog/"&gt;http://www.georgestarcher.com/splunk-success-with-syslog/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jul 2017 22:17:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Should-each-device-sending-data-have-a-different-UDP-input-port/m-p/295136#M56068</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-07-04T22:17:40Z</dc:date>
    </item>
  </channel>
</rss>

