All Apps and Add-ons

Not getting any data

pollo123
New Member

I'm trying to configure UDP Data input, can't configure port 514 and I am not getting any data, can someone help please? I read the README, but still not getting anything. Thanks.

0 Karma

pollo123
New Member

I can get data now with sourcetype syslog in the regular Splunk search using UDP (Port 514)but not in the Juniper SRX dashboard. I read from an answer to another question I should change the sourcetype to srx_log, I changed that under data input but still did not get any traffic.

0 Karma

pollo123
New Member

I can get data now with sourcetype syslog in the regular Splunk search using UDP (Port 514)but not in the Juniper SRX dashboard. I read from an answer to another question I should change the sourcetype to srx_log, I changed that under data input but still did not get any traffic.

0 Karma

DTERM
Contributor

Here are a few hints, I hope they are helpful.

  1. On your splunk host, ensure that IPTables is not turned on.
  2. From the splunk client, try a UDP nmap command to the host, here is an example nmap -sU -p 9997 -P0 myhost.mydomain.com
  3. On the splunk client run TCPDump to ensure you are seeing the data arrive.

If none of those work, you may want to look at your configuration. Hope that helps.

0 Karma

pollo123
New Member

I can get data now with sourcetype syslog in the regular Splunk search using UDP (Port 514)but not in the Juniper SRX dashboard. I read from an answer to another question I should change the sourcetype to srx_log, I changed that under data input but still did not get any traffic.

0 Karma

pollo123
New Member

I am getting an error message: port 514 is unavailable. What does this mean? I'm using a trial version. Am I missing a license or permissions?

0 Karma

Takajian
Builder

Can you confirm if firewall of your platform is disabled and splunk is listening with udp:514?

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

Can you elaborate on what the exact steps you took were, and the nature of the failure you encountered? It would be helpful if we could understand the specifics of the problem.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...