Getting Data In
Highlighted

Can't see my Syslog Source

Engager

Real simple one this I'm sure.

I want to monitor syslog of my router. I have gone to Manager->Data inputs->TCP Did port 514, host=IP, source type: Manual, syslog, Index: deafault

This is literally all I have done. If I load up a simple syslog monitor tool then this gets logs from the server.

I can't seem to view these logs anywhere though, it does show me any sources if I use the search app.

Where have I gone wrong?

Tags (1)
0 Karma
Highlighted

Re: Can't see my Syslog Source

Engager

Fixed, needs to be UDP!

Highlighted

Re: Can't see my Syslog Source

Splunk Employee
Splunk Employee

it CAN be TCP as well. You just need to make sure that you are sending the data as TCP though.

0 Karma