<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I not getting syslogs on port 512? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-getting-syslogs-on-port-512/m-p/310158#M58281</link>
    <description>&lt;P&gt;If you are not running the Splunk process as "root" you will not be able to access port below 1024 on Linux systems.&lt;/P&gt;

&lt;P&gt;On Windows, do a netstat -na and look for port 514 to be "listening"&lt;/P&gt;

&lt;P&gt;Also, what is the destination index you have set for the syslog data? Have you tried index=*  sourcetype="syslog" ?&lt;/P&gt;</description>
    <pubDate>Mon, 02 Apr 2018 21:53:50 GMT</pubDate>
    <dc:creator>chaker</dc:creator>
    <dc:date>2018-04-02T21:53:50Z</dc:date>
    <item>
      <title>Why am I not getting syslogs on port 512?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-getting-syslogs-on-port-512/m-p/310156#M58279</link>
      <description>&lt;P&gt;I am new to Splunk and I have it installed on my PC at work. I have Aruba Clear Pass syslog target set to forward to my PC's IP on port 512, UDP.&lt;BR /&gt;
Search field in Splunk is : source="udp:512" sourcetype="syslog". Not getting any results when I run a search.&lt;/P&gt;

&lt;P&gt;I tried port 514, UDP as well and still getting nothing. Wondering if its an IOS version issue as I'm running Windows 7 on my PC?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 14:46:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-getting-syslogs-on-port-512/m-p/310156#M58279</guid>
      <dc:creator>tabbtharrington</dc:creator>
      <dc:date>2018-04-02T14:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not getting syslogs on port 512?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-getting-syslogs-on-port-512/m-p/310157#M58280</link>
      <description>&lt;OL&gt;
&lt;LI&gt;Do you have Windows firewall active and configured to allow 512/udp traffic to pass through?&lt;/LI&gt;
&lt;LI&gt;Do you have a Splunk listener &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.3/Data/Monitornetworkports#Configure_a_UDP_input"&gt;configured to listen&lt;/A&gt; on port 512?&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 02 Apr 2018 21:43:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-getting-syslogs-on-port-512/m-p/310157#M58280</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2018-04-02T21:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I not getting syslogs on port 512?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-getting-syslogs-on-port-512/m-p/310158#M58281</link>
      <description>&lt;P&gt;If you are not running the Splunk process as "root" you will not be able to access port below 1024 on Linux systems.&lt;/P&gt;

&lt;P&gt;On Windows, do a netstat -na and look for port 514 to be "listening"&lt;/P&gt;

&lt;P&gt;Also, what is the destination index you have set for the syslog data? Have you tried index=*  sourcetype="syslog" ?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Apr 2018 21:53:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-not-getting-syslogs-on-port-512/m-p/310158#M58281</guid>
      <dc:creator>chaker</dc:creator>
      <dc:date>2018-04-02T21:53:50Z</dc:date>
    </item>
  </channel>
</rss>

