Getting Data In

Cymphonix Network Composer Logging Issue

afields
New Member

We are running Splunk for Windows 4.3 on Windows Server 2008 R2 x64. We are trying to pull Syslog data from a Cymphonix Network Composer EX350 unit (software version 9.2.4), via UDP port 521 (514 is in use by a WatchGuard Firewall unit).

The Cymphonix unit is pointing to the correct IP address for the Splunk server, and a Data Input on the Splunk server is configured to listen on UDP port 521. However, we are receiving no events/data from that Data Input.

I realize that this may very well be a Cymphonix issue, not a Splunk one, however I would like to cover all my bases here. Has anyone had experiencing configuring Splunk to work with a Cymphonix unit (or other such UDP unit)?

Tags (2)
0 Karma

dwaddle
SplunkTrust
SplunkTrust

Make sure port 521/udp is open on your Win64 host firewall. If not, it'll obviously be blocked and you'll never see it. Then, check with a sniffer ( http://www.wireshark.org ) to see the packets coming through. Note: Typically, wireshark will see/sniff packets before the firewall gets to filter them, which is why I suggested to check the firewall first.

dwaddle
SplunkTrust
SplunkTrust

Then, arguably ... either the Cymphonix isn't sending data on that port, or it's getting lost somewhere on the network between the two. It's hard for Splunk to index that which the network adapter never receives.

afields
New Member

Verified inbound rule in Windows Firewall allowing UDP Port 521 (although firewall is off).

WireShark capture shows no UDP packets coming from the Cymphonix IP to the Splunk IP.

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...