Deployment Architecture

universal forwarder on windows not forwarding SYSLOG

mikefoti
Communicator

So far I have been unable to get the universal forwarder to forward any events via syslog.

After initial install, using wireshark, I did see TCP being sent out. But since I only want to foward via syslog, using UDP port 514, I edited \local\outputs.conf so it includes only these lines:

[syslog]
defaultGroup = PrdIndexer_udp514

[syslog:PrdIndexer_udp514]
disabled = false
server = 123.456.789.123:514

I restarted the windows "SplunkForwader" service and still see no UDP/514 leaving the box.

Tags (1)
0 Karma
1 Solution

araitz
Splunk Employee
Splunk Employee

araitz
Splunk Employee
Splunk Employee

I think you are overlooking this:

http://splunk-base.splunk.com/answers/28991/universal-forwarder-send-syslog-to-a-thrid-party/29181

"Universal Forwarders do not Forward Syslog."

0 Karma

mikefoti
Communicator

Thanks araitz... I re-read that link and do see one thing I overlooked before... but not sure if its significant.

This statement...
Note: If you have defined multiple event types for syslog data, the event type names must all include the string "syslog".

I believe the only time might have affected "event types" would have been during the initial install when I selected to monitor/forward events from the local windows System eventlog. So, do I need to re-specify what needs monitored and forwarded so that the syslog forwarding engine becomes aware?

0 Karma

mikefoti
Communicator

Only 8 views and 0 answers!?!?!

I
m not sure if my question is too difficult, lacks enough detail or maybe has been asked/answered too many times.

Anybody have any advice?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...