I'm evaluating splunk specifically to work with MailFoundry syslogs. I have splunk setup and it's reading local logs, no problem. Problem: can't get it grab files from the remote MailFoundry server. Semi-clueless MailFoundry support tell me that the appliance uses UDP port 514 for syslog output. This port is open between the machines, but I'm getting the error:
"Encountered the following error while trying to save: In handler 'udp': Parameter name: UDP port 514 is not available.
I get the same error when trying TCP 25.
Any advice? Any MailFoundry users?
Nowdata,
Two possible reasons:
Hope this helps.
> please upvote and accept answer if you find it useful - thanks!