<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Graylog sending to SPLUNK over 9997 in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387929#M94568</link>
    <description>&lt;P&gt;I have Graylog forwarding to a UF over port 9997 and I see events streaming in but not being picked up by SPLUNK. I have a inputs.conf set to [splunktcp:9997] . I tried to setup a syslog.conf to tream to a file but realized that is port 514 and 9997. Can any one provide some debugging hints? &lt;BR /&gt;
How can I see if the events are getting picked up by the UF and just not forwarding?&lt;BR /&gt;
I looked in the Metrics.log but see nothing, is that the correct place to look?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jun 2018 11:16:52 GMT</pubDate>
    <dc:creator>pfabrizi</dc:creator>
    <dc:date>2018-06-19T11:16:52Z</dc:date>
    <item>
      <title>Graylog sending to SPLUNK over 9997</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387929#M94568</link>
      <description>&lt;P&gt;I have Graylog forwarding to a UF over port 9997 and I see events streaming in but not being picked up by SPLUNK. I have a inputs.conf set to [splunktcp:9997] . I tried to setup a syslog.conf to tream to a file but realized that is port 514 and 9997. Can any one provide some debugging hints? &lt;BR /&gt;
How can I see if the events are getting picked up by the UF and just not forwarding?&lt;BR /&gt;
I looked in the Metrics.log but see nothing, is that the correct place to look?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 11:16:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387929#M94568</guid>
      <dc:creator>pfabrizi</dc:creator>
      <dc:date>2018-06-19T11:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Graylog sending to SPLUNK over 9997</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387930#M94569</link>
      <description>&lt;P&gt;Sorry, I wasn't seeing this yesterday but I am today.&lt;/P&gt;

&lt;P&gt;06-19-2018 07:16:00.830 -0400 ERROR TcpInputProc - Message rejected. Received unexpected message of size=842019128 bytes from src=10.00.0.7:52640 in streaming mode. Maximum message size allowed=67108864. (::) Possible invalid source sending data to splunktcp port or valid source sending unsupported payload.&lt;/P&gt;

&lt;P&gt;I am going to go back to our Graylog folks and see if they can decrease the payload, is this correct?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 11:20:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387930#M94569</guid>
      <dc:creator>pfabrizi</dc:creator>
      <dc:date>2018-06-19T11:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: Graylog sending to SPLUNK over 9997</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387931#M94570</link>
      <description>&lt;P&gt;You are trying to send to a port that expects the (proprietary) Splunk-2-Splunk protocol; the message indicates that: "Possible invalid source sending data to splunktcp port". It will not understand the wire format Graylog is using.&lt;BR /&gt;
You may be more successful by creating a &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.1/Data/Monitornetworkports"&gt;network input&lt;/A&gt; for a different port and use that as your Graylog destination. &lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 21:48:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387931#M94570</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2018-06-19T21:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Graylog sending to SPLUNK over 9997</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387932#M94571</link>
      <description>&lt;P&gt;Hi SSIEVENT,&lt;BR /&gt;
                   I was just thinking that and in the process to tell the Graylog folks to send under another port. I am using a UF, so I have no UI, but i should be able to setup a inputs.conf with a tcp listener.&lt;/P&gt;

&lt;P&gt;Thank You!&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 22:10:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387932#M94571</guid>
      <dc:creator>pfabrizi</dc:creator>
      <dc:date>2018-06-19T22:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: Graylog sending to SPLUNK over 9997</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387933#M94572</link>
      <description>&lt;P&gt;Usually the port 9997 is used for the splunk protocol splunktcp. (only used by splunk forwarders)&lt;BR /&gt;
If your "graylog" software is sending logs, it is probably not using this protocol.&lt;/P&gt;

&lt;P&gt;looking at the internet, it seems that some people created code to have graylog send data over TCP to splunk :&lt;BR /&gt;
&lt;A href="https://github.com/graylog-labs/graylog-plugin-splunk"&gt;https://github.com/graylog-labs/graylog-plugin-splunk&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If it is sending data as syslog , please setup splunk to listen to UDP or TCP on a different port, and try send the data to it to see. (you may have to create a sourcetype to get proper event parsing)&lt;/P&gt;

&lt;P&gt;If the graylog is able to send data to a splunk HEC "http event collector" API, try to setup such an input on splunk, grab the token, and use it to configure the graylog sender.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 22:50:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387933#M94572</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2018-06-19T22:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: Graylog sending to SPLUNK over 9997</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387934#M94573</link>
      <description>&lt;P&gt;The link I sent also includes instructions on &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.1/Data/Monitornetworkports#Add_a_network_input_using_inputs.conf"&gt;how to do it using inputs.conf (or the CLI)&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 23:12:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387934#M94573</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2018-06-19T23:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: Graylog sending to SPLUNK over 9997</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387935#M94574</link>
      <description>&lt;P&gt;OK, I changed the port to 9996. I see it listening on that port. I no longer get the error messages but I am not seeing any data flow to indexer. &lt;BR /&gt;
am I missing anything?  This is running on a Linux UF.&lt;/P&gt;

&lt;P&gt;This is my inputs.conf&lt;BR /&gt;
[tcp://9996]&lt;BR /&gt;
index=wineventlog&lt;/P&gt;

&lt;P&gt;I see these messages in the metrics.log but don't know what they mean.&lt;/P&gt;

&lt;P&gt;06-20-2018 10:35:13.269 -0400 INFO  Metrics - group=tcpin_connections, 10.xx.xx.4:51718:9996, connectionType=raw, sourcePort=51718, sourceHost=server.doamin.net, sourceIp=10.xx.xx.4, destPort=9996, kb=0.00, _tcp_Bps=0.00, _tcp_KBps=0.00, _tcp_avg_thruput=0.01, _tcp_Kprocessed=2.14, _tcp_eps=0.00, _process_time_ms=0, evt_misc_kBps=0.00, evt_raw_kBps=0.00, evt_fields_kBps=0.00, evt_fn_kBps=0.00, evt_fv_kBps=0.00, evt_fn_str_kBps=0.00, evt_fn_meta_dyn_kBps=0.00, evt_fn_meta_predef_kBps=0.00, evt_fn_meta_str_kBps=0.00, evt_fv_num_kBps=0.00, evt_fv_str_kBps=0.00, evt_fv_predef_kBps=0.00, evt_fv_offlen_kBps=0.00, evt_fv_fp_kBps=0.00&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:06:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387935#M94574</guid>
      <dc:creator>pfabrizi</dc:creator>
      <dc:date>2020-09-29T20:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: Graylog sending to SPLUNK over 9997</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387936#M94575</link>
      <description>&lt;P&gt;So we see some connections coming in. (do the sum of kb over some time to see the volume).&lt;/P&gt;

&lt;P&gt;now you need to get a proper parsing.&lt;BR /&gt;
- define a sourcetype on your input on the UF&lt;BR /&gt;
- on the indexers, define the sourcetype in props.conf with the proper rules to : break the events, find the timestamp, consider multiline events, define the timezone etc..&lt;/P&gt;

&lt;P&gt;If you are not sure, try with sourcetype=syslog (on the UF) and see what it does.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 16:14:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387936#M94575</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2018-06-20T16:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Graylog sending to SPLUNK over 9997</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387937#M94576</link>
      <description>&lt;P&gt;Thank You!&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 09:52:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Graylog-sending-to-SPLUNK-over-9997/m-p/387937#M94576</guid>
      <dc:creator>pfabrizi</dc:creator>
      <dc:date>2018-06-21T09:52:17Z</dc:date>
    </item>
  </channel>
</rss>

