Getting Data In

Setting up syslog on a wireless router

John_neville
New Member

I have configured Splunk to capture syslog data on UDP:514 of my router but do not see any log data being captured, nor do I see it as a "Source" of data captured in in the "All Indexed data" of the Manager summary screen. I do see the local sources displayed here, but not the network port 514.

When I enter the command "splunk list udp" it comes back saying it is listening on port 514

Any suggestions would be appreciated - Thanks - John

Tags (1)
0 Karma

kjpearsall
New Member

Is udp port 514 open on the firewall of the machine that Splunk is listening on?

0 Karma

ziegfried
Influencer

Have you configured the router to send the data over to Splunk? Can you validate that data is arriving using something like Wireshark? Maybe the router is sending data over TCP?

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...