All Apps and Add-ons

Help on onboarding data

blbr123
Path Finder

Hi All,

How to onboard Tandem XMA data to splunk?

Labels (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @blbr123,

I didn't used Tandem XMA before, but in general, you have to understand how Tandem XMA can send its logs (e.g. syslog or Forwarders) and then configure Splunk to receive them.

Reading here (https://xypro.com/secure-database-management/from-zero-to-hero-integrate-hpe-nonstop-with-splunk/) it seems that you can configure Tandem XMA to send syslogs using TCP or UDP protocol, so you have to:

  • check the firewall routes between tandem XMS devices and Splunk,
  • configure Splunk syslog receiving [Settings -- Inputs -- Network Inputs -- New] or eventually using "Splunk Connect for syslog" App (https://splunkbase.splunk.com/app/4740/),
  • configure Tamdem XMA to send logs to the Splunk server.

If you didn't configured Splunk syslog receiving before, you can see the following videos and documents:

https://docs.splunk.com/Documentation/SplunkCloud/8.2.2112/Data/HowSplunkEnterprisehandlessyslogdata

https://www.splunk.com/en_us/blog/tips-and-tricks/using-syslog-ng-with-splunk.html

https://www.youtube.com/watch?v=iJ1iBZdXt2o

https://www.youtube.com/watch?v=BQU-bsSCXhk

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @blbr123,

I didn't used Tandem XMA before, but in general, you have to understand how Tandem XMA can send its logs (e.g. syslog or Forwarders) and then configure Splunk to receive them.

Reading here (https://xypro.com/secure-database-management/from-zero-to-hero-integrate-hpe-nonstop-with-splunk/) it seems that you can configure Tandem XMA to send syslogs using TCP or UDP protocol, so you have to:

  • check the firewall routes between tandem XMS devices and Splunk,
  • configure Splunk syslog receiving [Settings -- Inputs -- Network Inputs -- New] or eventually using "Splunk Connect for syslog" App (https://splunkbase.splunk.com/app/4740/),
  • configure Tamdem XMA to send logs to the Splunk server.

If you didn't configured Splunk syslog receiving before, you can see the following videos and documents:

https://docs.splunk.com/Documentation/SplunkCloud/8.2.2112/Data/HowSplunkEnterprisehandlessyslogdata

https://www.splunk.com/en_us/blog/tips-and-tricks/using-syslog-ng-with-splunk.html

https://www.youtube.com/watch?v=iJ1iBZdXt2o

https://www.youtube.com/watch?v=BQU-bsSCXhk

Ciao.

Giuseppe

0 Karma

blbr123
Path Finder

@gcusello Thank you for the response, Actually I already went through the link and was looking to see if there is any additional information available on this.

So looks like I have to onboard it using SC4S only as it's a syslog data.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @blbr123,

syslog isn't the most efficient way to take logs, but it's one of the most used and easier to configure.

Try it and let me know.

Remember that you can ingest syslogs only runtime, this means that, if you need to be sure to take all the logs, you have to configure an High Avalilability architecture: in few words, you need at least two Splunk servers (called Heavy Forwarders) with a Load balancer to take the syslogs.

Ciao.

Giuseppe

0 Karma

blbr123
Path Finder

@gcusello sure will check the possibilities and try and let you know.

Thank you.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @blbr123,

good for you, let me know and see next time!

Ciao and happy splunking.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...