Getting Data In

Splunk listens for syslog but no logs show up in the console

local_graph_2
New Member

I am running Splunk on Windows 7 64 bit and configured data adapters for syslog on TCP and UDP. I can see via Wireshark that syslog is making it to the main interface, Splunk is listening on 0.0.0.0:514 but I do not see any logs at all in Splunk and I verified splunkd is listening and I verified traffic is making it to the Win7 server

Tags (1)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

0.0.0.0 indicates that it's listening on all network adapters.

View solution in original post

0 Karma

local_graph_2
New Member

For Windows 7 you actually have to have the firewall on, not disabled, and create a rule allowing syslog traffic.

Took me way to long to figure that out, but hey, at least the next guy will know right?

This works now

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

0.0.0.0 indicates that it's listening on all network adapters.

0 Karma

local_graph_2
New Member

I used Wireshark on Windows 7 to see the syslog via the 192.168.x.x interface, Windows firewall is off by default as this is within a closed subnet

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Most of the time, you have to disable or configure the firewall on Windows 7.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

What did you do to ascertain that your syslog traffic was making it to the Windows 7 desktop?

0 Karma

local_graph_2
New Member

So this was my thought as well, but I do not see any logs at all in Splunk and I verified splunkd is listening and I verified traffic is making it to the Win7 server.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...