<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP requirement for syslog transfer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497568#M84854</link>
    <description>&lt;P&gt;Have you config of sending syslog client? Definitely it sounds like it sends events over tcp instead of udp.&lt;/P&gt;

&lt;P&gt;R. Ismo &lt;/P&gt;</description>
    <pubDate>Wed, 29 Jan 2020 21:35:43 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2020-01-29T21:35:43Z</dc:date>
    <item>
      <title>TCP requirement for syslog transfer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497562#M84848</link>
      <description>&lt;P&gt;Syslogs are sent on UDP port 514 towards Syslog-ng&lt;/P&gt;

&lt;P&gt;But we have experienced if tcp for port 514 is not working/not open, syslogs are not transferred&lt;/P&gt;

&lt;P&gt;As soon tcp is fixed, syslogs start transferring and validation is successful !&lt;/P&gt;

&lt;P&gt;Can someone explain why it is like this/how this works?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 08:08:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497562#M84848</guid>
      <dc:creator>jibin1988</dc:creator>
      <dc:date>2020-01-29T08:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: TCP requirement for syslog transfer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497563#M84849</link>
      <description>&lt;P&gt;Hi @jibin1988,&lt;BR /&gt;
are you sure about this?&lt;BR /&gt;
I have experienced many times that opening only UDP port (enabling UDP network input), syslogs arrive.&lt;/P&gt;

&lt;P&gt;Another question, you speak about syslog-ng, but are you receiving syslogs using syslog-ng or Splunk input?&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 09:13:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497563#M84849</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-01-29T09:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: TCP requirement for syslog transfer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497564#M84850</link>
      <description>&lt;P&gt;Hi Giuseppe ,&lt;/P&gt;

&lt;P&gt;We have experienced this situation, Already UDP port 514 was open and still device was not reporting. after troubleshooting for long hours we opened TCP port and device started sending logs.&lt;/P&gt;

&lt;P&gt;And yes we are using syslog-ng for collecting the logs not Splunk input.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Jibin&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 12:22:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497564#M84850</guid>
      <dc:creator>jibin1988</dc:creator>
      <dc:date>2020-01-29T12:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: TCP requirement for syslog transfer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497565#M84851</link>
      <description>&lt;P&gt;Hi @jibin1988,&lt;BR /&gt;
in this case I'm not able to support you, you need a network expert not a Splunk expert!&lt;BR /&gt;
At the same time, I hint to try the Splunk network inputs, I'm very satisfied!&lt;/P&gt;

&lt;P&gt;Ciaoand next time.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 12:32:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497565#M84851</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-01-29T12:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: TCP requirement for syslog transfer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497566#M84852</link>
      <description>&lt;P&gt;Syslog can be either TCP or UDP - are you sure that in your case that syslog was not using TCP transport instead of UDP?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 12:33:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497566#M84852</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-01-29T12:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: TCP requirement for syslog transfer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497567#M84853</link>
      <description>&lt;P&gt;Maybe you have a Load Balancer that health checks if TCP is working and if not it doesn't load balance the syslog traffic?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 13:57:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497567#M84853</guid>
      <dc:creator>gfreitas</dc:creator>
      <dc:date>2020-01-29T13:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: TCP requirement for syslog transfer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497568#M84854</link>
      <description>&lt;P&gt;Have you config of sending syslog client? Definitely it sounds like it sends events over tcp instead of udp.&lt;/P&gt;

&lt;P&gt;R. Ismo &lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 21:35:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497568#M84854</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-01-29T21:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: TCP requirement for syslog transfer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497569#M84855</link>
      <description>&lt;P&gt;You can can use netcat (&lt;STRONG&gt;nc&lt;/STRONG&gt;) command to test sending messages to either TCP or UDP 514 or other ports on the Linux command line.&lt;/P&gt;

&lt;P&gt;Example commands (replace localhost with your ip or fqdn) if not testing directly on the same server which hosts the syslog service.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;udp test to localhost&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;echo -n "&amp;lt;14&amp;gt;mytesthost This is a syslog ***UDP 514*** Test" | nc -u -w5 -v localhost 514
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;tcp test to localhost&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;echo -n "&amp;lt;14&amp;gt;mytesthost This is a syslog ***TCP 514*** Test" | nc -w5 -v localhost 514
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I also like this free testing tool for Windows (Essential NetTools) &lt;A href="https://www.tamos.com/download/main/"&gt;https://www.tamos.com/download/main/&lt;/A&gt;&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/8301i0B7B5AC2980308BA/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2020 05:38:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497569#M84855</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2020-01-30T05:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: TCP requirement for syslog transfer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497570#M84856</link>
      <description>&lt;P&gt;Hi Rob,&lt;/P&gt;

&lt;P&gt;I did that and we found udp port is open and tcp is closed using nc command.&lt;/P&gt;

&lt;P&gt;nc -vz  514 ---- Its connection time out&lt;BR /&gt;
nc - vzu  514 ---- Its succeeded!!&lt;/P&gt;

&lt;P&gt;So after this we opend tcp port as well and the logs started reporting.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2020 09:29:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497570#M84856</guid>
      <dc:creator>jibin1988</dc:creator>
      <dc:date>2020-01-30T09:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: TCP requirement for syslog transfer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497571#M84857</link>
      <description>&lt;P&gt;Thanks @gfreitas for your input.&lt;/P&gt;

&lt;P&gt;Yes we do have a LB in between, But how can we confirm that?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2020 09:32:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497571#M84857</guid>
      <dc:creator>jibin1988</dc:creator>
      <dc:date>2020-01-30T09:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: TCP requirement for syslog transfer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497572#M84858</link>
      <description>&lt;P&gt;I would say you need to check with whoever configured the LB.&lt;BR /&gt;
In general you can use tcpdump to monitor your syslog server and check for any packets arriving from the Load Balancer IPs on port 514 TCP. This might give you a confirmation that the LB is health checking the syslog server and therefore understanding it as down if no TCP connection is stablished.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2020 09:46:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497572#M84858</guid>
      <dc:creator>gfreitas</dc:creator>
      <dc:date>2020-01-30T09:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: TCP requirement for syslog transfer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497573#M84859</link>
      <description>&lt;P&gt;Right - but you are testing what RECEIVING ports are open - My comment is are you SURE you known what protocol syslog is being SENT on.&lt;/P&gt;

&lt;P&gt;tcpdump the sending machine and see what traffic is being sent on 514.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2020 09:55:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/TCP-requirement-for-syslog-transfer/m-p/497573#M84859</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-01-30T09:55:49Z</dc:date>
    </item>
  </channel>
</rss>

