Getting Data In

Splunk not getting syslogs.

deca2499
Engager

Hello all,

I am having a problem with my Splunk install that it has stopped accepting syslogs from my Cisco ASA. It was working until 2 days ago. I have the ASA sending the logs to the Splunk server. I am trying to get it back up and running so that I can try and get my ASA access lists worked on. The Splunk install is on a Windows 2016 server and I do not know much about Linux. I really do not want to blow it away and have to redo it all from scratch...  I know the server is getting the logs as I have Kiwi on the box as well and it shows the logs as they come in. The firewall is off on the Windows server as well. Can anyone help and point me in the right direction to find out what is going on and get it fixed?

Thanks!

Labels (2)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

Hi @deca2499,

If you are running Kiwi and Splunk together and both listening Cisco ASA UDP syslog data, only one of them can get it.  Is it possible you started Kiwi two days ago?

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @deca2499,

If you are running Kiwi and Splunk together and both listening Cisco ASA UDP syslog data, only one of them can get it.  Is it possible you started Kiwi two days ago?

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

deca2499
Engager

DANGIT! !   I didnt even think to look at the kiwi service that is on the server..  It was running, so it was probably getting them before Splunk.. I have now disabled the service and Splunk is getting what I was expected to...   Sometimes, you just have to look at the simple things.

 

Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...