All Apps and Add-ons

Cannot get logs from Firewall to the Splunk docker container

felipe_gonzalez
New Member

Hello team,

Need some help here, sure you guys are really.

White me with some inside on how I can use containers better.

Desired goal:

Get the logs from Firewall > Synology > Docker Container[splunk-splunk]

Actions Taken:

Logs are being sent out from origin: syslog server

Created an entry in the syslog server to send messages to IP:6515 (Synology DSM)

Modified port settings at Docker to have a Local port:6515 | Container port:9997

Docker bridge displays auto subnet 172.17.0/16 with gateway 172.17.0.1

Result:

At this moment I can access the Splunk web GUI under localhost:8000 with no problem, I see "ALL" logs tagged with a sourcing IP 172.17.0.1 that belongs to the bridge Gateway on the docker driver.

If the desired goal is to monitor the logs from the syslog server in a more verbose manner, how you guys advise configuring the receiving aspect of Docker (container/Splunk) to make this happen.

Log detail sample:

date_zone = local
host = 172.17.0.1
process = filterlog
source = udp:9997
sourcetype = syslog
splunk_server = 039974fdab5a
timeendpos = 15

0 Karma

felipe_gonzalez
New Member
0 Karma
Get Updates on the Splunk Community!

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...