Deployment Architecture

universal forwarder on windows not forwarding SYSLOG

mikefoti
Communicator

So far I have been unable to get the universal forwarder to forward any events via syslog.

After initial install, using wireshark, I did see TCP being sent out. But since I only want to foward via syslog, using UDP port 514, I edited \local\outputs.conf so it includes only these lines:

[syslog]
defaultGroup = PrdIndexer_udp514

[syslog:PrdIndexer_udp514]
disabled = false
server = 123.456.789.123:514

I restarted the windows "SplunkForwader" service and still see no UDP/514 leaving the box.

Tags (1)
0 Karma
1 Solution

araitz
Splunk Employee
Splunk Employee

araitz
Splunk Employee
Splunk Employee

I think you are overlooking this:

http://splunk-base.splunk.com/answers/28991/universal-forwarder-send-syslog-to-a-thrid-party/29181

"Universal Forwarders do not Forward Syslog."

0 Karma

mikefoti
Communicator

Thanks araitz... I re-read that link and do see one thing I overlooked before... but not sure if its significant.

This statement...
Note: If you have defined multiple event types for syslog data, the event type names must all include the string "syslog".

I believe the only time might have affected "event types" would have been during the initial install when I selected to monitor/forward events from the local windows System eventlog. So, do I need to re-specify what needs monitored and forwarded so that the syslog forwarding engine becomes aware?

0 Karma

mikefoti
Communicator

Only 8 views and 0 answers!?!?!

I
m not sure if my question is too difficult, lacks enough detail or maybe has been asked/answered too many times.

Anybody have any advice?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...