Getting Data In

SC4S not able to parse syslog and ingest

wayne333
New Member

I've set up my SC4S and connected to my indexer. Logs are ingested as show below but further down, those does not get ingested, I see them while im listening with tcpdump. What have I missed?

Ingested

<174>2025-08-27T10:46:46.743660+08:00 idrac-xxxxxxxxxx1 Severity: Informational, Category: Audit, MessageID: USR0031, Message: Unable to log in for root from xxx.xxx.xx.32 using GUI

 

Not ingested

<190>Aug 27 09:59:52 xxxxxxxxO-DSSW6605 raslogd: AUDIT, 2025/08/27-09:59:52 (+08), [SNMP-3020], INFO, SECURITY, NONE/admin/xxx.xxx.xx.153/snmp/snmp,NA/xxxxxxxxO-DSSW6605/FID 128, 9.2.2, , , , , , , Event: Login, Info: SNMP login attempt via IP: xxx.xxx.xx.153, Last accessed user: , Success count: 0, Failure count: 1292, Time: Wed Aug 27 09:59:48 2025

<174>Aug 27 11:12:01 xxxxxxxxo-xxxxx1 hsm[4519]: info : 0 : Command: sysconf time 11:13 20250827 : admin : xxx.xxx.xx.32/57827
11:13:00.706364 veth0 Out IP xxx.xxx.xx.170.57454 > 1x.xx.x.8.514: SYSLOG local5.info, length: 125

 

 

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @wayne333 
Are you able to confirm that these events haven’t been indexed into a fallback index incase they weren’t properly typed by SC4S?

 

 

🌟 Did this answer help you? If so, please consider:

    • Adding karma to show it was useful
    • Marking it as the solution if it resolved your issue
    • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing.

0 Karma

wayne333
New Member

Hi @livehybrid,
Thanks for your time.


Yes , have checked the other default SC4S indexes as well. These 2 products with the same format of logs. The logs provided are from Brocade and Thales which are also known vendors in SC4S. 

Did I miss anything other than listening to the port in the env file?

 

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...