Getting Data In

How to send syslog to sandbox?

vashidu
New Member

How can i send syslog from my cisco asa to the splunk sandbox?

Tags (1)
0 Karma
1 Solution

cgaspard_splunk
Splunk Employee
Splunk Employee

Currently Splunk Sandbox DOES support forwarding data via Universal Forwarders.

On the other hand, raw UDP SYSLOG forwarding directly to the Sandbox (without a Universal Forwarder) is not supported. This is done for good reasons. To forward SYSLOG data from a host, a Universal Forwarder can be installed and configured to monitor and push local SYSLOG to the Sandbox.

View solution in original post

cgaspard_splunk
Splunk Employee
Splunk Employee

Currently Splunk Sandbox DOES support forwarding data via Universal Forwarders.

On the other hand, raw UDP SYSLOG forwarding directly to the Sandbox (without a Universal Forwarder) is not supported. This is done for good reasons. To forward SYSLOG data from a host, a Universal Forwarder can be installed and configured to monitor and push local SYSLOG to the Sandbox.

fortiwhall
Explorer

It looks like Splunk Sandbox (which I believe is different than splunk storm or cloud) only supports uploading data via files. In the Splunk Sandbox instance I just spun up, the only "Add Data" option is to upload a file. I was also wanting to send some live SYSLOG from some of my devices up to the Sandbox, but it appears the only way to really do this is to log to your own server somewhere, take the log files, and then upload them to Sandbox.

Splunk sandbox is currently available off the front page of Splunk by clicking "Free Splunk" and then clicking the Free Online Sandbox link.
This is the direct link http://www.splunk.com/page/sign_up/cloudtrial?redirecturl=/getsplunk/cloudtrial&ac=test_modal_online...

ChrisG
Splunk Employee
Splunk Employee

This is correct. The online sandbox only supports file upload, not forwarding or monitoring.

0 Karma

MuS
SplunkTrust
SplunkTrust

MuS
SplunkTrust
SplunkTrust

Login to splunkstorm.com, select your project, click the data tab, under network data click select, then click authorize your IP address - done

0 Karma

vashidu
New Member

My cloud splunk must be missing a part of that then. Cant find that anywhere.

0 Karma

MuS
SplunkTrust
SplunkTrust

but because you were so keen and provided a lot of information, I was able to find the correct link http://docs.splunk.com/Documentation/Storm/latest/User/AdddataoverTCPorUDP

this includes a lot irony 😉

MuS
SplunkTrust
SplunkTrust

well you did not mention Splunk cloud at all 😉

0 Karma

vashidu
New Member

the linked document doesnt cover splunk cloud.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...