Getting Data In

How to troubleshoot why I'm not getting syslog data from Cisco ASA into Splunk?

jimmycher
Engager

I have a Cisco ASA that is pushing out syslog files to the server that SPLUNK resides on. I verified they are reaching the server with TCPDump. The data is not getting into SPLUNK. Does the server need to be set up as a a syslog server, or does SPLUNK perform that function? What should be my troubleshooting steps?

0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

Splunk CAN ingest syslog inputs directly. You would create a data input listening on UDP (and possibly TCP) on port 514 for syslog. But just because you can doesn't mean you should.

A better way to do this would be to set up a syslog server (rsyslog or syslog-ng for *nix, or on windows I think the kiwi syslog daemon may still be free for this purpose?) and use that to gather the syslog inputs into files, then configure Splunk to read those files.

Why? How? Someone else has written up some great info on this, so check here. Give that a shot and let us know how it went!

View solution in original post

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...