All Apps and Add-ons

Syncsort Ironstream - SYSLOG: How can I create connection between Ironstream and Splunk?

yasinbi
New Member

Hi,

I am a new customer on Splunk and trying to connect it with Ironstream on z/OS. My mainly purpose is taking syslog data from z/OS site to Splunk. But while creating a connection I need Splunk server and port definitions. Is there anyone who can show me the true customization way or any document you can suggest?

Thanks

Yasin

0 Karma
1 Solution

ianhss
Explorer

Hello Yasin,

You need to create a new TCP data input on your Splunk server.

  1. In Splunk, select the menu option: Settings > Data inputs
  2. Create a new TCP data input, and click New.
  3. In the Add Data screen, enter a Port number. This will be used for the incoming data.
  4. In the next panel, set the SourceType to: structured > _json. And, select an index (or create a new index).
  5. Configure Ironstream to send SYSLOG data to the Splunk server using the IP address of your server and the port specified above.

NOTE: Firewall or network issues may interfere with any connection.

If you have any problems, please contact our Support team: https://www.syncsort.com/support . They will be very happy to help.

View solution in original post

ianhss
Explorer

Hello Yasin,

You need to create a new TCP data input on your Splunk server.

  1. In Splunk, select the menu option: Settings > Data inputs
  2. Create a new TCP data input, and click New.
  3. In the Add Data screen, enter a Port number. This will be used for the incoming data.
  4. In the next panel, set the SourceType to: structured > _json. And, select an index (or create a new index).
  5. Configure Ironstream to send SYSLOG data to the Splunk server using the IP address of your server and the port specified above.

NOTE: Firewall or network issues may interfere with any connection.

If you have any problems, please contact our Support team: https://www.syncsort.com/support . They will be very happy to help.

yasinbi
New Member

Thank you for information. I am going to try in line with your instructions

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

Hi @yasinbi - Did ianhss' answer provide a working solution to your question? If yes, please don't forget to click "Accept" below the answer to resolve your post. If no, please provide feedback by leaving another comment. Thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...