Getting Data In

Splunk listens for syslog but no logs show up in the console

New Member

I am running Splunk on Windows 7 64 bit and configured data adapters for syslog on TCP and UDP. I can see via Wireshark that syslog is making it to the main interface, Splunk is listening on 0.0.0.0:514 but I do not see any logs at all in Splunk and I verified splunkd is listening and I verified traffic is making it to the Win7 server

Tags (1)
0 Karma
1 Solution

Splunk Employee
Splunk Employee

0.0.0.0 indicates that it's listening on all network adapters.

View solution in original post

0 Karma

New Member

For Windows 7 you actually have to have the firewall on, not disabled, and create a rule allowing syslog traffic.

Took me way to long to figure that out, but hey, at least the next guy will know right?

This works now

0 Karma

Splunk Employee
Splunk Employee

0.0.0.0 indicates that it's listening on all network adapters.

View solution in original post

0 Karma

New Member

I used Wireshark on Windows 7 to see the syslog via the 192.168.x.x interface, Windows firewall is off by default as this is within a closed subnet

0 Karma

Splunk Employee
Splunk Employee

Most of the time, you have to disable or configure the firewall on Windows 7.

0 Karma

Splunk Employee
Splunk Employee

What did you do to ascertain that your syslog traffic was making it to the Windows 7 desktop?

0 Karma

New Member

So this was my thought as well, but I do not see any logs at all in Splunk and I verified splunkd is listening and I verified traffic is making it to the Win7 server.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!