Deployment Architecture

Why am I unable to add a second input Parameter name and the UDP port 514 is not available?

Isaor
New Member

hello,
I am trying to add to my Splunk some Linux via syslog, but when I try to add the input separately it sends me the next error:

Parameter name: UDP port 514 is not available.

If I try to disable and add a new input it lets me do it, but I receive logs of only one input.

What could be the problem?.

My Splunk is installed on a windows server.

0 Karma

FrankVl
Ultra Champion

inputs.conf spec says explicitely that "Only one stanza per port number is currently supported." for UDP inputs.
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf#UDP:

0 Karma

janispelss
Path Finder

Are you trying to create a 2nd input using the same port? Only one input can be configured for each port.

0 Karma

Isaor
New Member

Hello Janispelss,

I tried to do that in splunk with SO Centos and works, but in splunk with Windows doesn´t works.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...