<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traffic getting to server, but not getting splunk'd. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Traffic-getting-to-server-but-not-getting-splunk-d/m-p/24003#M4354</link>
    <description>&lt;P&gt;I have an ASA firewall sending data to my splunk server (syslog port 514). When I run tcpdump...&lt;/P&gt;

&lt;H1&gt;tcpdump -i eth1 host 172.28.8.234 &amp;gt; test.txt&lt;/H1&gt;

&lt;P&gt;I get data dumped. It looks like...&lt;/P&gt;

&lt;P&gt;11:15:53.627144 IP 172.28.8.234.syslog &amp;gt; 172.28.60.163.syslog: SYSLOG local4.info, length: 145&lt;BR /&gt;
11:15:53.628353 IP 172.28.8.234.syslog &amp;gt; 172.28.60.163.syslog: SYSLOG local4.info, length: 146&lt;BR /&gt;
11:15:53.629599 IP 172.28.8.234.syslog &amp;gt; 172.28.60.163.syslog: SYSLOG local4.info, length: 181&lt;/P&gt;

&lt;P&gt;But when I search splunk for the ip 172.28.8.234, I get jack squat. What are some reasons splunk would not be logging this data? Splunk is listening on UDP port 514...&lt;/P&gt;

&lt;P&gt;~# nmap -sU localhost&lt;/P&gt;

&lt;P&gt;Starting Nmap 5.00 ( &lt;A href="http://nmap.org"&gt;http://nmap.org&lt;/A&gt; ) at 2013-05-03 11:20 EDT&lt;BR /&gt;
Warning: Hostname localhost resolves to 2 IPs. Using 127.0.0.1.&lt;BR /&gt;
Interesting ports on localhost (127.0.0.1):&lt;BR /&gt;
Not shown: 998 closed ports&lt;BR /&gt;
PORT    STATE         SERVICE&lt;BR /&gt;
123/udp open|filtered ntp&lt;BR /&gt;
514/udp open|filtered syslog&lt;/P&gt;</description>
    <pubDate>Fri, 03 May 2013 15:44:27 GMT</pubDate>
    <dc:creator>rblalock</dc:creator>
    <dc:date>2013-05-03T15:44:27Z</dc:date>
    <item>
      <title>Traffic getting to server, but not getting splunk'd.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Traffic-getting-to-server-but-not-getting-splunk-d/m-p/24003#M4354</link>
      <description>&lt;P&gt;I have an ASA firewall sending data to my splunk server (syslog port 514). When I run tcpdump...&lt;/P&gt;

&lt;H1&gt;tcpdump -i eth1 host 172.28.8.234 &amp;gt; test.txt&lt;/H1&gt;

&lt;P&gt;I get data dumped. It looks like...&lt;/P&gt;

&lt;P&gt;11:15:53.627144 IP 172.28.8.234.syslog &amp;gt; 172.28.60.163.syslog: SYSLOG local4.info, length: 145&lt;BR /&gt;
11:15:53.628353 IP 172.28.8.234.syslog &amp;gt; 172.28.60.163.syslog: SYSLOG local4.info, length: 146&lt;BR /&gt;
11:15:53.629599 IP 172.28.8.234.syslog &amp;gt; 172.28.60.163.syslog: SYSLOG local4.info, length: 181&lt;/P&gt;

&lt;P&gt;But when I search splunk for the ip 172.28.8.234, I get jack squat. What are some reasons splunk would not be logging this data? Splunk is listening on UDP port 514...&lt;/P&gt;

&lt;P&gt;~# nmap -sU localhost&lt;/P&gt;

&lt;P&gt;Starting Nmap 5.00 ( &lt;A href="http://nmap.org"&gt;http://nmap.org&lt;/A&gt; ) at 2013-05-03 11:20 EDT&lt;BR /&gt;
Warning: Hostname localhost resolves to 2 IPs. Using 127.0.0.1.&lt;BR /&gt;
Interesting ports on localhost (127.0.0.1):&lt;BR /&gt;
Not shown: 998 closed ports&lt;BR /&gt;
PORT    STATE         SERVICE&lt;BR /&gt;
123/udp open|filtered ntp&lt;BR /&gt;
514/udp open|filtered syslog&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2013 15:44:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Traffic-getting-to-server-but-not-getting-splunk-d/m-p/24003#M4354</guid>
      <dc:creator>rblalock</dc:creator>
      <dc:date>2013-05-03T15:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic getting to server, but not getting splunk'd.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Traffic-getting-to-server-but-not-getting-splunk-d/m-p/24004#M4355</link>
      <description>&lt;P&gt;check this answer to see if it applies to your case:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/12876/splunk-running-on-my-linux-server-is-only-showing-me-events-from-my-local-subnet-what-is-going-on"&gt;http://splunk-base.splunk.com/answers/12876/splunk-running-on-my-linux-server-is-only-showing-me-events-from-my-local-subnet-what-is-going-on&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2013 15:46:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Traffic-getting-to-server-but-not-getting-splunk-d/m-p/24004#M4355</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-05-03T15:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic getting to server, but not getting splunk'd.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Traffic-getting-to-server-but-not-getting-splunk-d/m-p/24005#M4356</link>
      <description>&lt;P&gt;Also the data with sourcetype 'syslog' gets its host value from the host value specified in the events, which is not necessarily the same as the IP address of the host the events were received from.&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2013 15:58:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Traffic-getting-to-server-but-not-getting-splunk-d/m-p/24005#M4356</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-05-03T15:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic getting to server, but not getting splunk'd.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Traffic-getting-to-server-but-not-getting-splunk-d/m-p/24006#M4357</link>
      <description>&lt;P&gt;Excellent. Thanks very much.&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2013 17:52:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Traffic-getting-to-server-but-not-getting-splunk-d/m-p/24006#M4357</guid>
      <dc:creator>rblalock</dc:creator>
      <dc:date>2013-05-03T17:52:05Z</dc:date>
    </item>
  </channel>
</rss>

