All Apps and Add-ons

Syncsort Ironstream - SYSLOG: How can I create connection between Ironstream and Splunk?

yasinbi
New Member

Hi,

I am a new customer on Splunk and trying to connect it with Ironstream on z/OS. My mainly purpose is taking syslog data from z/OS site to Splunk. But while creating a connection I need Splunk server and port definitions. Is there anyone who can show me the true customization way or any document you can suggest?

Thanks

Yasin

0 Karma
1 Solution

ianhss
Explorer

Hello Yasin,

You need to create a new TCP data input on your Splunk server.

  1. In Splunk, select the menu option: Settings > Data inputs
  2. Create a new TCP data input, and click New.
  3. In the Add Data screen, enter a Port number. This will be used for the incoming data.
  4. In the next panel, set the SourceType to: structured > _json. And, select an index (or create a new index).
  5. Configure Ironstream to send SYSLOG data to the Splunk server using the IP address of your server and the port specified above.

NOTE: Firewall or network issues may interfere with any connection.

If you have any problems, please contact our Support team: https://www.syncsort.com/support . They will be very happy to help.

View solution in original post

ianhss
Explorer

Hello Yasin,

You need to create a new TCP data input on your Splunk server.

  1. In Splunk, select the menu option: Settings > Data inputs
  2. Create a new TCP data input, and click New.
  3. In the Add Data screen, enter a Port number. This will be used for the incoming data.
  4. In the next panel, set the SourceType to: structured > _json. And, select an index (or create a new index).
  5. Configure Ironstream to send SYSLOG data to the Splunk server using the IP address of your server and the port specified above.

NOTE: Firewall or network issues may interfere with any connection.

If you have any problems, please contact our Support team: https://www.syncsort.com/support . They will be very happy to help.

yasinbi
New Member

Thank you for information. I am going to try in line with your instructions

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

Hi @yasinbi - Did ianhss' answer provide a working solution to your question? If yes, please don't forget to click "Accept" below the answer to resolve your post. If no, please provide feedback by leaving another comment. Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...