Getting Data In

Cymphonix Network Composer Logging Issue

afields
New Member

We are running Splunk for Windows 4.3 on Windows Server 2008 R2 x64. We are trying to pull Syslog data from a Cymphonix Network Composer EX350 unit (software version 9.2.4), via UDP port 521 (514 is in use by a WatchGuard Firewall unit).

The Cymphonix unit is pointing to the correct IP address for the Splunk server, and a Data Input on the Splunk server is configured to listen on UDP port 521. However, we are receiving no events/data from that Data Input.

I realize that this may very well be a Cymphonix issue, not a Splunk one, however I would like to cover all my bases here. Has anyone had experiencing configuring Splunk to work with a Cymphonix unit (or other such UDP unit)?

Tags (2)
0 Karma

dwaddle
SplunkTrust
SplunkTrust

Make sure port 521/udp is open on your Win64 host firewall. If not, it'll obviously be blocked and you'll never see it. Then, check with a sniffer ( http://www.wireshark.org ) to see the packets coming through. Note: Typically, wireshark will see/sniff packets before the firewall gets to filter them, which is why I suggested to check the firewall first.

dwaddle
SplunkTrust
SplunkTrust

Then, arguably ... either the Cymphonix isn't sending data on that port, or it's getting lost somewhere on the network between the two. It's hard for Splunk to index that which the network adapter never receives.

afields
New Member

Verified inbound rule in Windows Firewall allowing UDP Port 521 (although firewall is off).

WireShark capture shows no UDP packets coming from the Cymphonix IP to the Splunk IP.

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...