Getting Data In

SC4S not able to parse syslog and ingest

wayne333
New Member

I've set up my SC4S and connected to my indexer. Logs are ingested as show below but further down, those does not get ingested, I see them while im listening with tcpdump. What have I missed?

Ingested

<174>2025-08-27T10:46:46.743660+08:00 idrac-xxxxxxxxxx1 Severity: Informational, Category: Audit, MessageID: USR0031, Message: Unable to log in for root from xxx.xxx.xx.32 using GUI

 

Not ingested

<190>Aug 27 09:59:52 xxxxxxxxO-DSSW6605 raslogd: AUDIT, 2025/08/27-09:59:52 (+08), [SNMP-3020], INFO, SECURITY, NONE/admin/xxx.xxx.xx.153/snmp/snmp,NA/xxxxxxxxO-DSSW6605/FID 128, 9.2.2, , , , , , , Event: Login, Info: SNMP login attempt via IP: xxx.xxx.xx.153, Last accessed user: , Success count: 0, Failure count: 1292, Time: Wed Aug 27 09:59:48 2025

<174>Aug 27 11:12:01 xxxxxxxxo-xxxxx1 hsm[4519]: info : 0 : Command: sysconf time 11:13 20250827 : admin : xxx.xxx.xx.32/57827
11:13:00.706364 veth0 Out IP xxx.xxx.xx.170.57454 > 1x.xx.x.8.514: SYSLOG local5.info, length: 125

 

 

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @wayne333 
Are you able to confirm that these events haven’t been indexed into a fallback index incase they weren’t properly typed by SC4S?

 

 

🌟 Did this answer help you? If so, please consider:

    • Adding karma to show it was useful
    • Marking it as the solution if it resolved your issue
    • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing.

0 Karma

wayne333
New Member

Hi @livehybrid,
Thanks for your time.


Yes , have checked the other default SC4S indexes as well. These 2 products with the same format of logs. The logs provided are from Brocade and Thales which are also known vendors in SC4S. 

Did I miss anything other than listening to the port in the env file?

 

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...