Getting Data In

SC4S not able to parse syslog and ingest

wayne333
Explorer

I've set up my SC4S and connected to my indexer. Logs are ingested as show below but further down, those does not get ingested, I see them while im listening with tcpdump. What have I missed?

Ingested

<174>2025-08-27T10:46:46.743660+08:00 idrac-xxxxxxxxxx1 Severity: Informational, Category: Audit, MessageID: USR0031, Message: Unable to log in for root from xxx.xxx.xx.32 using GUI

 

Not ingested

<190>Aug 27 09:59:52 xxxxxxxxO-DSSW6605 raslogd: AUDIT, 2025/08/27-09:59:52 (+08), [SNMP-3020], INFO, SECURITY, NONE/admin/xxx.xxx.xx.153/snmp/snmp,NA/xxxxxxxxO-DSSW6605/FID 128, 9.2.2, , , , , , , Event: Login, Info: SNMP login attempt via IP: xxx.xxx.xx.153, Last accessed user: , Success count: 0, Failure count: 1292, Time: Wed Aug 27 09:59:48 2025

<174>Aug 27 11:12:01 xxxxxxxxo-xxxxx1 hsm[4519]: info : 0 : Command: sysconf time 11:13 20250827 : admin : xxx.xxx.xx.32/57827
11:13:00.706364 veth0 Out IP xxx.xxx.xx.170.57454 > 1x.xx.x.8.514: SYSLOG local5.info, length: 125

 

 

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @wayne333 
Are you able to confirm that these events haven’t been indexed into a fallback index incase they weren’t properly typed by SC4S?

 

 

🌟 Did this answer help you? If so, please consider:

    • Adding karma to show it was useful
    • Marking it as the solution if it resolved your issue
    • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing.

0 Karma

wayne333
Explorer

Hi @livehybrid,
Thanks for your time.


Yes , have checked the other default SC4S indexes as well. These 2 products with the same format of logs. The logs provided are from Brocade and Thales which are also known vendors in SC4S. 

Did I miss anything other than listening to the port in the env file?

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...