I am fairly new with Splunk, and I'm trying to set up Splunk to listen to UDP 514 for syslog messages. Can anyone explain in simple words, how to do this, and if you could list the steps?
thanks
See http://docs.splunk.com/Documentation/Splunk/6.3.2/Data/Monitornetworkports
Following the instructions, it created the following line syntax:
search source="udp:514" index="history" sourcetype="Network Switches"
How long does it normally takes for data to start to appear. Several of my network switches have been setup to send logging information to the Splunk Server.
Thanks
The search will display data within seconds of it being indexed by Splunk. The key factor is how often your network switches send log info. If data doesn't appear, check your firewall(s).