Getting Data In

Getting error when entering port number for a receiver in new installation

pexelva
Engager

I get the following error when I try to add a receiver with port 9997 or 514.

The following error was reported: SyntaxError: Unexpected token '<', " <p class=""... is not valid JSON.

I get the same error no matter what port I try to enter.  This is a new installation and this is the first thing I tried to do.  I am somewhat of a novice with splunk.

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Splunk has "free" licenses and "trial" licenses (also free) with different capabilities.  Which do you have?

Splunk forwarders typically send data to Splunk indexers on port 9997.

Splunk can receive syslog data on port 514, but it's not recommended.  To set that up, go to Settings->Data inputs->TCP (or UDP, if you prefer) and click the green button.  Then fill in the form and click Save.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

We need more information.  How exactly are you trying to add a receiver port?  What command are you issuing and where are you entering it?

---
If this reply helps you, Karma would be appreciated.
0 Karma

pexelva
Engager

I have an Enterprise free trial system that I installed on an Ubuntu Server.  In the gui I went to the settings>forwarding and receiving>receiving>add new because I am going to try and set up a forwarder.   On the Add New page I entered 514 in the Listen on this port field.  I get the rror after I click save.

I want to use this for gathering syslog data from my OPNsense router and then build a dashboard for it.

 

I also keep getting this message when trying change settings  CSRF validation failed

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk has "free" licenses and "trial" licenses (also free) with different capabilities.  Which do you have?

Splunk forwarders typically send data to Splunk indexers on port 9997.

Splunk can receive syslog data on port 514, but it's not recommended.  To set that up, go to Settings->Data inputs->TCP (or UDP, if you prefer) and click the green button.  Then fill in the form and click Save.

---
If this reply helps you, Karma would be appreciated.
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...