Getting Data In

Not receiving readable logs from Brocade Switches

nairv
Explorer

We have added brocade switches to heavy forwarder via tcp:6514. We are able to receive the logs , but not in a readable format.

\x00a\x00\x00]"e8H,W\xCC\xA7az\xB9\xFF\xFB \xFE\x9E\x8C
֋\xC5\xCBhQ\x8E\xD1a{\x00\x00 \x00=\x005\x00<\x00/\x00
\x00\xFF\x00\x00(\x00#\x00\x00\x00
\x00 \x00

input.conf
[tcp://6514]
connection_host = dns
index = san
sourcetype = BROCADE_SWITCH

settings in Brocade switch

-secure -port 6514 to the syslogadmin --setip cmd

Switch type
2 model type 6520's
4 model type 5480
2 model- bvlfcsw100/200

Tags (1)
0 Karma
1 Solution

nairv
Explorer

The brocade switch has to be always pointed to UDP 514 in HF or UF. If we point towards any other port like how I was using TCP 6514 we receive only encrypted data and non readable since it becomes secured port.

View solution in original post

0 Karma

nairv
Explorer

The brocade switch has to be always pointed to UDP 514 in HF or UF. If we point towards any other port like how I was using TCP 6514 we receive only encrypted data and non readable since it becomes secured port.

0 Karma

nairv
Explorer

The issue has been solved now I am able to get readable logs from the brocade..

0 Karma

adonio
Ultra Champion

@nairv please share what you did to solve your challenge so others can learn

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...