All Apps and Add-ons

Syncsort Ironstream - SYSLOG: How can I create connection between Ironstream and Splunk?

yasinbi
New Member

Hi,

I am a new customer on Splunk and trying to connect it with Ironstream on z/OS. My mainly purpose is taking syslog data from z/OS site to Splunk. But while creating a connection I need Splunk server and port definitions. Is there anyone who can show me the true customization way or any document you can suggest?

Thanks

Yasin

0 Karma
1 Solution

ianhss
Explorer

Hello Yasin,

You need to create a new TCP data input on your Splunk server.

  1. In Splunk, select the menu option: Settings > Data inputs
  2. Create a new TCP data input, and click New.
  3. In the Add Data screen, enter a Port number. This will be used for the incoming data.
  4. In the next panel, set the SourceType to: structured > _json. And, select an index (or create a new index).
  5. Configure Ironstream to send SYSLOG data to the Splunk server using the IP address of your server and the port specified above.

NOTE: Firewall or network issues may interfere with any connection.

If you have any problems, please contact our Support team: https://www.syncsort.com/support . They will be very happy to help.

View solution in original post

ianhss
Explorer

Hello Yasin,

You need to create a new TCP data input on your Splunk server.

  1. In Splunk, select the menu option: Settings > Data inputs
  2. Create a new TCP data input, and click New.
  3. In the Add Data screen, enter a Port number. This will be used for the incoming data.
  4. In the next panel, set the SourceType to: structured > _json. And, select an index (or create a new index).
  5. Configure Ironstream to send SYSLOG data to the Splunk server using the IP address of your server and the port specified above.

NOTE: Firewall or network issues may interfere with any connection.

If you have any problems, please contact our Support team: https://www.syncsort.com/support . They will be very happy to help.

yasinbi
New Member

Thank you for information. I am going to try in line with your instructions

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

Hi @yasinbi - Did ianhss' answer provide a working solution to your question? If yes, please don't forget to click "Accept" below the answer to resolve your post. If no, please provide feedback by leaving another comment. Thanks!

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...