<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Clearpass App for splunk via syslog but doasn't work in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Clearpass-App-for-splunk-via-syslog-but-doasn-t-work/m-p/523686#M88423</link>
    <description>&lt;P&gt;Hi everybody&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I installed the Clearpass TA application on my SH instance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;it collects logs via syslogs. So here is the configuration of my inputs.conf of the application&lt;/P&gt;&lt;P&gt;[udp://4514]&lt;BR /&gt;sourcetype = Aruba:CPPM:Syslog&lt;BR /&gt;index = cg93_clearpass&lt;/P&gt;&lt;P&gt;I restarted the service, but&amp;nbsp;no log appears.&amp;nbsp;&lt;/P&gt;&lt;P&gt;On my syslog server, I ran the following command :&amp;nbsp;tcpdump -i eth0 port 4514&lt;BR /&gt;We can see that the logs have arrived at the splunk syslog server&lt;/P&gt;&lt;P&gt;Do you know where it can come from?&lt;/P&gt;</description>
    <pubDate>Thu, 08 Oct 2020 12:41:54 GMT</pubDate>
    <dc:creator>sdurao</dc:creator>
    <dc:date>2020-10-08T12:41:54Z</dc:date>
    <item>
      <title>Clearpass App for splunk via syslog but doasn't work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Clearpass-App-for-splunk-via-syslog-but-doasn-t-work/m-p/523686#M88423</link>
      <description>&lt;P&gt;Hi everybody&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I installed the Clearpass TA application on my SH instance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;it collects logs via syslogs. So here is the configuration of my inputs.conf of the application&lt;/P&gt;&lt;P&gt;[udp://4514]&lt;BR /&gt;sourcetype = Aruba:CPPM:Syslog&lt;BR /&gt;index = cg93_clearpass&lt;/P&gt;&lt;P&gt;I restarted the service, but&amp;nbsp;no log appears.&amp;nbsp;&lt;/P&gt;&lt;P&gt;On my syslog server, I ran the following command :&amp;nbsp;tcpdump -i eth0 port 4514&lt;BR /&gt;We can see that the logs have arrived at the splunk syslog server&lt;/P&gt;&lt;P&gt;Do you know where it can come from?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 12:41:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Clearpass-App-for-splunk-via-syslog-but-doasn-t-work/m-p/523686#M88423</guid>
      <dc:creator>sdurao</dc:creator>
      <dc:date>2020-10-08T12:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: Clearpass App for splunk via syslog but doasn't work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Clearpass-App-for-splunk-via-syslog-but-doasn-t-work/m-p/523729#M88427</link>
      <description>&lt;P&gt;How does the data get from the syslog server to Splunk?&amp;nbsp; The UDP input probably is not it.&amp;nbsp; Do you have a universal forwarder on the syslog server?&amp;nbsp; That's the usual practice.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 15:20:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Clearpass-App-for-splunk-via-syslog-but-doasn-t-work/m-p/523729#M88427</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-10-08T15:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: Clearpass App for splunk via syslog but doasn't work</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Clearpass-App-for-splunk-via-syslog-but-doasn-t-work/m-p/523861#M88457</link>
      <description>&lt;P&gt;&lt;SPAN&gt;They are transmitted via the UDP port to our Splunk syslog server.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;On the Clearpass application, UDP port 4514 has been entered.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;When you type the tcpudump command (tcpdump -i eth0 port 4514), you can see that it receives the frames on the syslog. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Yes we have an UF on the Syslog server.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, I have the impression that it does not send them to the indexer. &lt;/SPAN&gt;&lt;SPAN&gt;How can I correct this?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2020 07:35:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Clearpass-App-for-splunk-via-syslog-but-doasn-t-work/m-p/523861#M88457</guid>
      <dc:creator>sdurao</dc:creator>
      <dc:date>2020-10-09T07:35:31Z</dc:date>
    </item>
  </channel>
</rss>

