<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Syslog Configuration through Splunk Web? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Syslog-Configuration-through-Splunk-Web/m-p/457022#M8627</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;we are planning to get the Syslog data into Splunk Heavy Forwarders. They are Appliances and those are hardened linux OS.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;till now i have done the following steps&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I have provided the Splunk Heavy Forwarder IP to App owner, they configured the syslog on their end&lt;/P&gt;

&lt;P&gt;I created Data inputs on HFW by giving TCP: 1024, Sourcetype, IP and created Index. (514 already being used) &lt;/P&gt;

&lt;P&gt;I could't able able to find the data yet on splunk. is this the correct process OR am i missing anything? please let me know if i did anything wrong or if I need to add some inputs?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
    <pubDate>Wed, 27 Mar 2019 11:03:56 GMT</pubDate>
    <dc:creator>niha1318</dc:creator>
    <dc:date>2019-03-27T11:03:56Z</dc:date>
    <item>
      <title>Syslog Configuration through Splunk Web?</title>
      <link>https://community.splunk.com/t5/Installation/Syslog-Configuration-through-Splunk-Web/m-p/457022#M8627</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;we are planning to get the Syslog data into Splunk Heavy Forwarders. They are Appliances and those are hardened linux OS.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;till now i have done the following steps&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I have provided the Splunk Heavy Forwarder IP to App owner, they configured the syslog on their end&lt;/P&gt;

&lt;P&gt;I created Data inputs on HFW by giving TCP: 1024, Sourcetype, IP and created Index. (514 already being used) &lt;/P&gt;

&lt;P&gt;I could't able able to find the data yet on splunk. is this the correct process OR am i missing anything? please let me know if i did anything wrong or if I need to add some inputs?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 11:03:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Syslog-Configuration-through-Splunk-Web/m-p/457022#M8627</guid>
      <dc:creator>niha1318</dc:creator>
      <dc:date>2019-03-27T11:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Configuration through Splunk Web?</title>
      <link>https://community.splunk.com/t5/Installation/Syslog-Configuration-through-Splunk-Web/m-p/457023#M8628</link>
      <description>&lt;P&gt;Do you have local firewalls blocking TCP 1024. Are you sure you are sending data to the right port? &lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 00:42:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Syslog-Configuration-through-Splunk-Web/m-p/457023#M8628</guid>
      <dc:creator>sduff_splunk</dc:creator>
      <dc:date>2019-03-28T00:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Configuration through Splunk Web?</title>
      <link>https://community.splunk.com/t5/Installation/Syslog-Configuration-through-Splunk-Web/m-p/457024#M8629</link>
      <description>&lt;P&gt;if that is the case, I hope it will through the Firewall Error. but I didn't get any firewall error.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 09:32:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Syslog-Configuration-through-Splunk-Web/m-p/457024#M8629</guid>
      <dc:creator>niha1318</dc:creator>
      <dc:date>2019-03-28T09:32:53Z</dc:date>
    </item>
  </channel>
</rss>

