- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Get data from forward TCP and UDP ports
king311
Loves-to-Learn
01-12-2022
06:00 AM
Not getting data ofter configuring TCP 80 port in inputs.conf
my stanza is like this
[tcp://80]
connection_host = dns
index = port
sourcetype = syslog
can you give me any idea on this. thnks in advance.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
isoutamo

SplunkTrust
01-12-2022
06:22 AM
If you are using port less or equal than 1024 then you must run splunkd as root, which is not as best practices. I prefer to use e.g. port 1514 or similar for that.
Have you update also your senders to use that unstandardised port (normally udp + 514) to use?
r. Ismo
