Getting Data In

Sending syslog from MachineA to ServerB..Thru port 514. Not successful.

limwesiang
Engager

Can anyone give me any hint about this? I have splunk installed in ServerB, Windows server 2008 and i have MachineA, XP. I hope to send the syslog from MachineA to ServerB thru port 514. To be make sure that, port 514 is listening in ServerB. Besides, i set it up thru the syslog by TCP port as following the document guide. But yet, i still cant get any results from that.

Tags (1)
0 Karma

lguinn2
Legend

First, can you telnet from MachineA to ServerB?

Is the port open in the firewall on both MachineA and ServerB?

Are there any firewalls between the servers that might be blocking access?

Is MachineA sending syslog via TCP or UDP? The usual default for syslog is UDP, although it depends on how it is configured.

limwesiang
Engager

BTW, thanks a lot for your answer. appreciate of it.

0 Karma

limwesiang
Engager

Yup. it is ok to telnet from MachineA to ServerB.
Besides, the port is also listening..
yes, finally i figure out the problem is because the serverB is not allowed to receive from network...therefore, it is worked after i allow it.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Federated Search for Dynamic Data Self Storage Is Now Generally Available on Splunk ...

 Splunk is excited to announce the General Availability of Federated Search for Dynamic Data Self Storage ...

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...