Getting Data In

Manually created inputs.conf and still no data

kluey
Explorer

I installed the add-on and tried to follow the directions. After installing, there was no 'Set up' as stated in the readme file, so I manually created the inputs.conf and added lines below (Note: These are the only lines in the inputs.conf file):

\Splunk\etc\apps\Splunk_Ciscofirewalls\local\inputs.conf

[udp://514]
disabled = false

I restarted Splunk and still no data. Anyone have luck with this? I am on Splunk 5 and the overview states it is supported.

0 Karma

yannK
Splunk Employee
Splunk Employee

Here are some basic questions :

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...