Getting Data In

How to configure OSX Syslogd ??

splunkminiuser
Engager

Hi to all,

I've tried to configure my OSX Splunk server so it will accept data from the syslog deamon (see: https://wiki.splunk.com/Community:HowTo_Configure_Mac_OS_X_Syslog_To_Forward_Data).

I've edited the /etc/syslog.conf file and added ". x.x.x.x". (Where x.x.x.x is the IP of my machine where Splunk should be listening).

After that, I stopped and restarted the Syslog Deamon (as explained in the tutorial).

When I log into Splunk, there is no data. Splunk tells me: "waiting for data".
Do I need to configure Splunk to "receive" the data? And how do I do that?

Thanks in advance!

Tags (2)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

To receive syslog events directly you need to tell Splunk to listen to them: http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

To receive syslog events directly you need to tell Splunk to listen to them: http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...