<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Getting UDP data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Getting-UDP-data/m-p/551709#M91564</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This is default standalone setup. I'm trying to get data in from a network device which sends data as syslog on UDP/5114.&lt;/P&gt;&lt;P&gt;I've configured the UDP/5114 on Splunk. Here are the screenshots of config.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="udp_data_input" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14162i14BD551D5A6098B6/image-size/large?v=v2&amp;amp;px=999" role="button" title="udp_data_input.JPG" alt="udp_data_input" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;udp_data_input&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="udp_data_input_details" style="width: 851px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14163i43F3191D3124CD31/image-size/large?v=v2&amp;amp;px=999" role="button" title="udp_data_input_details.JPG" alt="udp_data_input_details" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;udp_data_input_details&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I've confirmed that splunk process is listening on port 5114&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="udp_listener" style="width: 820px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14164i969B0E1167DEE02E/image-size/large?v=v2&amp;amp;px=999" role="button" title="udp_listener.JPG" alt="udp_listener" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;udp_listener&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I've also confirmed that I'm getting data on host so no network routing or firewall issue. Bellow is a screenshot of MS Network monitor showing data received on port UDP/5114.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="data_on_5114" style="width: 913px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14165i0A3ACE45DC9364F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="data_on_5114.JPG" alt="data_on_5114" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;data_on_5114&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Yet no data is coming in the splunk instance.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="no_events_in_splunk" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14166i11C20BF0357B6E60/image-size/large?v=v2&amp;amp;px=999" role="button" title="no_events_in_splunk.JPG" alt="no_events_in_splunk" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;no_events_in_splunk&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pls help resolve this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards.&lt;/P&gt;</description>
    <pubDate>Sat, 15 May 2021 14:43:28 GMT</pubDate>
    <dc:creator>nikhil</dc:creator>
    <dc:date>2021-05-15T14:43:28Z</dc:date>
    <item>
      <title>Getting UDP data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-UDP-data/m-p/551709#M91564</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This is default standalone setup. I'm trying to get data in from a network device which sends data as syslog on UDP/5114.&lt;/P&gt;&lt;P&gt;I've configured the UDP/5114 on Splunk. Here are the screenshots of config.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="udp_data_input" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14162i14BD551D5A6098B6/image-size/large?v=v2&amp;amp;px=999" role="button" title="udp_data_input.JPG" alt="udp_data_input" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;udp_data_input&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="udp_data_input_details" style="width: 851px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14163i43F3191D3124CD31/image-size/large?v=v2&amp;amp;px=999" role="button" title="udp_data_input_details.JPG" alt="udp_data_input_details" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;udp_data_input_details&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I've confirmed that splunk process is listening on port 5114&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="udp_listener" style="width: 820px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14164i969B0E1167DEE02E/image-size/large?v=v2&amp;amp;px=999" role="button" title="udp_listener.JPG" alt="udp_listener" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;udp_listener&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I've also confirmed that I'm getting data on host so no network routing or firewall issue. Bellow is a screenshot of MS Network monitor showing data received on port UDP/5114.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="data_on_5114" style="width: 913px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14165i0A3ACE45DC9364F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="data_on_5114.JPG" alt="data_on_5114" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;data_on_5114&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Yet no data is coming in the splunk instance.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="no_events_in_splunk" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/14166i11C20BF0357B6E60/image-size/large?v=v2&amp;amp;px=999" role="button" title="no_events_in_splunk.JPG" alt="no_events_in_splunk" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;no_events_in_splunk&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pls help resolve this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards.&lt;/P&gt;</description>
      <pubDate>Sat, 15 May 2021 14:43:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-UDP-data/m-p/551709#M91564</guid>
      <dc:creator>nikhil</dc:creator>
      <dc:date>2021-05-15T14:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Getting UDP data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-UDP-data/m-p/551710#M91565</link>
      <description>&lt;P&gt;Have you considered using Splunk Connect for Syslog (SC4S)?&lt;/P&gt;</description>
      <pubDate>Sat, 15 May 2021 15:24:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-UDP-data/m-p/551710#M91565</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-05-15T15:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: Getting UDP data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-UDP-data/m-p/551711#M91566</link>
      <description>&lt;P&gt;Considering now. Any comment on the mentioned config.? Is there anything I'm missing in config.? Or any other troubleshooting pointers.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards.&lt;/P&gt;</description>
      <pubDate>Sat, 15 May 2021 15:31:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-UDP-data/m-p/551711#M91566</guid>
      <dc:creator>nikhil</dc:creator>
      <dc:date>2021-05-15T15:31:19Z</dc:date>
    </item>
    <item>
      <title>Re: Getting UDP data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-UDP-data/m-p/551731#M91568</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Will SC4S(Splunk Connector for Syslog) be supported on my setup.? Do I need separate linux instance for the same.?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My Splunk Setup:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Splunk Enterprise Server &lt;/SPAN&gt;&lt;SPAN class="splunk-version"&gt;8.1.3&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Windows, 8 GB Physical Memory, 2 CPU Cores&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Mode: Standalone&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;--&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks &amp;amp; Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 16 May 2021 05:51:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-UDP-data/m-p/551731#M91568</guid>
      <dc:creator>nikhil</dc:creator>
      <dc:date>2021-05-16T05:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: Getting UDP data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-UDP-data/m-p/551986#M91611</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;Can anyone pls help on this.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 08:24:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-UDP-data/m-p/551986#M91611</guid>
      <dc:creator>nikhil</dc:creator>
      <dc:date>2021-05-18T08:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: Getting UDP data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Getting-UDP-data/m-p/552001#M91616</link>
      <description>&lt;P&gt;I'm not sure about MS Network Monitor (now deprecated btw) - never used it - but Wireshark, for example, just dumps packets from the network interface. Which doesn't mean that they don't get filtered on a host firewall afterwards.&lt;/P&gt;&lt;P&gt;Since you're using UDP which is stateless, connectionless and so on, unless you're actively denying the packets (sending ICMPs), there will be nothing on the network informing you whether the recipient received the packets correctly or not.&lt;/P&gt;&lt;P&gt;So I'd search the firewall rules again.&lt;/P&gt;&lt;P&gt;And two more remarks:&lt;/P&gt;&lt;P&gt;1) If possible, use TCP - it's much more reliable and less prone to event loss&lt;/P&gt;&lt;P&gt;2) Splunk's syslog inputs don't scale well so if you're planning on having big volumes of data ingested this way, consider other forms of providing the source data to Splunk - there are a few methods that can be used (for example - a syslog server writing to buffer file and UF reading that file or a syslog server receiving the events and pushing them to HEC input via HTTP).&lt;/P&gt;&lt;P&gt;But to have something to begin with Splunk's syslog inputs are OK.&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 09:27:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Getting-UDP-data/m-p/552001#M91616</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-05-18T09:27:19Z</dc:date>
    </item>
  </channel>
</rss>

