Deployment Architecture

Why is Syslog not listening to port 6514?

debjit_k
Path Finder

There is a scenario like one of our trend micro DDA is not reporting to our syslog server.

Why it is not reporting 

Previously we use port 514 and now we are using port 6514 but 6514 is not reporting to syslog. And we want both the listening port 514 and 6514.

My question 

1. Can we have both the port open on our syslog I.e. 514 and 6514 

2. How to enable the port listing on our syslog for the port 6514 

 

Thank you 

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @debjit_k,

are you speaking of enabling a port syslog receiving in Splunk or using a different system (e.g. r-syslog)?

if you are speaking of Splunk syslog receiving, you can enable on Splunk al the ports you like, but only the ones permitted by your operative system.

If a port is already in use, you have an error in Splunk, but it's configurable by conf file instead by GUI.

So the real questions are:

  • can the Operative system of the receiver use the 6514 port?
  • can the sender send logs on port 6514?

As you can see the question isn't more on Splunk, but outside it.

Ciao.

Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...