We are running Splunk for Windows 4.3 on Windows Server 2008 R2 x64. We are trying to pull Syslog data from a Cymphonix Network Composer EX350 unit (software version 9.2.4), via UDP port 521 (514 is in use by a WatchGuard Firewall unit).
The Cymphonix unit is pointing to the correct IP address for the Splunk server, and a Data Input on the Splunk server is configured to listen on UDP port 521. However, we are receiving no events/data from that Data Input.
I realize that this may very well be a Cymphonix issue, not a Splunk one, however I would like to cover all my bases here. Has anyone had experiencing configuring Splunk to work with a Cymphonix unit (or other such UDP unit)?
Make sure port 521/udp is open on your Win64 host firewall. If not, it'll obviously be blocked and you'll never see it. Then, check with a sniffer ( http://www.wireshark.org ) to see the packets coming through. Note: Typically, wireshark will see/sniff packets before the firewall gets to filter them, which is why I suggested to check the firewall first.
Then, arguably ... either the Cymphonix isn't sending data on that port, or it's getting lost somewhere on the network between the two. It's hard for Splunk to index that which the network adapter never receives.
Verified inbound rule in Windows Firewall allowing UDP Port 521 (although firewall is off).
WireShark capture shows no UDP packets coming from the Cymphonix IP to the Splunk IP.