Not getting data ofter configuring TCP 80 port in inputs.conf
my stanza is like this
[tcp://80]
connection_host = dns
index = port
sourcetype = syslog
can you give me any idea on this. thnks in advance.
If you are using port less or equal than 1024 then you must run splunkd as root, which is not as best practices. I prefer to use e.g. port 1514 or similar for that.
Have you update also your senders to use that unstandardised port (normally udp + 514) to use?
r. Ismo