Deployment Architecture

Why am I unable to add a second input Parameter name and the UDP port 514 is not available?

Isaor
New Member

hello,
I am trying to add to my Splunk some Linux via syslog, but when I try to add the input separately it sends me the next error:

Parameter name: UDP port 514 is not available.

If I try to disable and add a new input it lets me do it, but I receive logs of only one input.

What could be the problem?.

My Splunk is installed on a windows server.

0 Karma

FrankVl
Ultra Champion

inputs.conf spec says explicitely that "Only one stanza per port number is currently supported." for UDP inputs.
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf#UDP:

0 Karma

janispelss
Path Finder

Are you trying to create a 2nd input using the same port? Only one input can be configured for each port.

0 Karma

Isaor
New Member

Hello Janispelss,

I tried to do that in splunk with SO Centos and works, but in splunk with Windows doesn´t works.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...