<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error while adding more than 1 Cisco device in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Error-while-adding-more-than-1-Cisco-device/m-p/546711#M91044</link>
    <description>&lt;P&gt;Hello there. Consider using &amp;nbsp;&lt;A href="https://splunk-connect-for-syslog.readthedocs.io/en/master/gettingstarted/" target="_self"&gt;Splunk Connect for Syslog&lt;/A&gt;. It is a tool that will allow very easy implementation of datasources like Cisco through syslog-ng. It will ultimately write to HTTP Event Collector in Splunk.&lt;/P&gt;&lt;P&gt;See &lt;A href="https://www.splunk.com/en_us/blog/tips-and-tricks/splunk-connect-for-syslog-turnkey-and-scalable-syslog-gdi.html" target="_self"&gt;this link&lt;/A&gt; for additional information. I hope this helps because I have been having great success with this tool!&lt;/P&gt;</description>
    <pubDate>Mon, 05 Apr 2021 13:35:54 GMT</pubDate>
    <dc:creator>brentw</dc:creator>
    <dc:date>2021-04-05T13:35:54Z</dc:date>
    <item>
      <title>Error while adding more than 1 Cisco device</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-while-adding-more-than-1-Cisco-device/m-p/546702#M91042</link>
      <description>&lt;P&gt;Dear Experts,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to add the data to monitor Cisco logs through Splunk, i am just able to add 1 device only, it is giving error when i am adding more devices.&lt;/P&gt;&lt;P&gt;Snapshot of the error is shown below.&lt;/P&gt;&lt;P&gt;Any help regarding this will be appreciated.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jfk87_0-1617622559625.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/13610i89A9AE2C61069870/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jfk87_0-1617622559625.png" alt="jfk87_0-1617622559625.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Apr 2021 11:41:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-while-adding-more-than-1-Cisco-device/m-p/546702#M91042</guid>
      <dc:creator>jfk87</dc:creator>
      <dc:date>2021-04-05T11:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Error while adding more than 1 Cisco device</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-while-adding-more-than-1-Cisco-device/m-p/546707#M91043</link>
      <description>&lt;P&gt;It would help if you explained the steps to reproduce this problem, but I suspect you are doing at least two things wrong:&lt;/P&gt;&lt;P&gt;1) Trying to send syslog events directly to Splunk.&amp;nbsp; This has been discouraged for a few years because it can lead to data loss.&amp;nbsp; Best Practice is to send syslog events to a dedicated syslog server and forward them from there to Splunk.&lt;/P&gt;&lt;P&gt;2) Assuming there is a one-to-one relationship between a UDP port and a network device.&amp;nbsp; This is not the case.&amp;nbsp; Once Splunk is listening to a port, it will accept data from thousands of devices, provided they match the "&lt;SPAN&gt;Only accept connection from" setting.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Apr 2021 12:46:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-while-adding-more-than-1-Cisco-device/m-p/546707#M91043</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-04-05T12:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Error while adding more than 1 Cisco device</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-while-adding-more-than-1-Cisco-device/m-p/546711#M91044</link>
      <description>&lt;P&gt;Hello there. Consider using &amp;nbsp;&lt;A href="https://splunk-connect-for-syslog.readthedocs.io/en/master/gettingstarted/" target="_self"&gt;Splunk Connect for Syslog&lt;/A&gt;. It is a tool that will allow very easy implementation of datasources like Cisco through syslog-ng. It will ultimately write to HTTP Event Collector in Splunk.&lt;/P&gt;&lt;P&gt;See &lt;A href="https://www.splunk.com/en_us/blog/tips-and-tricks/splunk-connect-for-syslog-turnkey-and-scalable-syslog-gdi.html" target="_self"&gt;this link&lt;/A&gt; for additional information. I hope this helps because I have been having great success with this tool!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Apr 2021 13:35:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-while-adding-more-than-1-Cisco-device/m-p/546711#M91044</guid>
      <dc:creator>brentw</dc:creator>
      <dc:date>2021-04-05T13:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Error while adding more than 1 Cisco device</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-while-adding-more-than-1-Cisco-device/m-p/546804#M91051</link>
      <description>&lt;P&gt;It can be reproduce by doing the following,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Add Data &amp;gt; Monitor &amp;gt; TCP/UDP &amp;gt; then mention the port udp/514 and add any IP address in Only accept connection from field.&lt;/P&gt;&lt;P&gt;It is just accepting one device, and when i am trying to add another device, it is showing an error, as was mentioned in the snap in my last post.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 06:59:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-while-adding-more-than-1-Cisco-device/m-p/546804#M91051</guid>
      <dc:creator>jfk87</dc:creator>
      <dc:date>2021-04-06T06:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: Error while adding more than 1 Cisco device</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-while-adding-more-than-1-Cisco-device/m-p/546806#M91052</link>
      <description>&lt;P&gt;Thanks, have to check it.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 07:06:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-while-adding-more-than-1-Cisco-device/m-p/546806#M91052</guid>
      <dc:creator>jfk87</dc:creator>
      <dc:date>2021-04-06T07:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: Error while adding more than 1 Cisco device</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-while-adding-more-than-1-Cisco-device/m-p/547731#M91133</link>
      <description>&lt;P&gt;Will be thankful if there is any help regarding this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 08:27:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-while-adding-more-than-1-Cisco-device/m-p/547731#M91133</guid>
      <dc:creator>jfk87</dc:creator>
      <dc:date>2021-04-13T08:27:15Z</dc:date>
    </item>
    <item>
      <title>Re: Error while adding more than 1 Cisco device</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Error-while-adding-more-than-1-Cisco-device/m-p/547755#M91135</link>
      <description>&lt;P&gt;Did you read point #2 in my answer?&amp;nbsp; It doesn't make sense to add the same port multiple times.&amp;nbsp; Once Splunk is listening to a port there is no need to tell it to do so again.&lt;/P&gt;&lt;P&gt;Please describe the problem you are trying to solve.&amp;nbsp; What is it that adding another port 514 input will do for you?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 12:30:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Error-while-adding-more-than-1-Cisco-device/m-p/547755#M91135</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-04-13T12:30:45Z</dc:date>
    </item>
  </channel>
</rss>

