Getting Data In

How to configure OSX Syslogd ??

splunkminiuser
Engager

Hi to all,

I've tried to configure my OSX Splunk server so it will accept data from the syslog deamon (see: https://wiki.splunk.com/Community:HowTo_Configure_Mac_OS_X_Syslog_To_Forward_Data).

I've edited the /etc/syslog.conf file and added ". x.x.x.x". (Where x.x.x.x is the IP of my machine where Splunk should be listening).

After that, I stopped and restarted the Syslog Deamon (as explained in the tutorial).

When I log into Splunk, there is no data. Splunk tells me: "waiting for data".
Do I need to configure Splunk to "receive" the data? And how do I do that?

Thanks in advance!

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

To receive syslog events directly you need to tell Splunk to listen to them: http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

To receive syslog events directly you need to tell Splunk to listen to them: http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...