Getting Data In

How to get logs from Brocade into Splunk?

AzmathShaik
Path Finder

Hello

is any one working on brocade?? how to get logs from brocade to splunk???

Tags (1)
0 Karma

guarisma
Contributor

Brocade switches, as most devices do, have a Syslog module you can enable

http://www.brocade.com/content/html/en/administration-guide/fos-740-admin/GUID-80B201B9-C5F5-4FC3-90...

You can send the logs to a centralized syslog server that then forwards (a Heavy Forwarder) the logs to Splunk, or you can send the logs directly to Splunk using a UDP or TCP input.

0 Karma

dogan
New Member

Hello,

I want to send syslog entrees to splunk directly. The config is done with the command "syslogadmin --set -ip xxx.xxx.xxxx.xxx -port 65456. Here is the configuration in place.
But it does not work
Are there other ports or other configuration to set up?
Any ideas ?
syslogadmin --show -ip
syslog.1 xxx.xxx.xxx.29 port 65456
syslog.2 xxx.xxx.xxx.30 port 65456
syslog.3 xxx.xxx.xxx.31 port 65456
syslog.4 xxx.xxx.xxx.80 port 65456

syslogadmin --show -facility
Syslog facility: LOG_LOCAL7

auditcfg --show -filter
Audit filter is enabled.
1-ZONE
2-SECURITY
3-CONFIGURATION
4-FIRMWARE
5-FABRIC
7-LS
8-CLI
9-MAPS
Severity level: INFO

0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. This is a very old thread. For better visibility you should rather start a new thread with a verbose description of your problem.

2. What does "doesn't work" mean? And did you do _any_ configuration on Splunk's side or do you just expect Splunk to work out of the blue?

3. As a side note - receiving syslog directly on Splunk component is not the recommended way. The recommended architecture is to use an external syslog daemon and either write to files from which you'll pick up the events with UF or send to HEC input.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...