Getting Data In

Syslog Level :Emerg - system is unusable

asingh90
Engager

Hi all, so i have been trying to set up the Home Monitor app and for a while nothing was being indexed so I i had a look on wireshark to see if anything was getting through and i got the following error

Level :Emerg - system is unusable (0).

I have configured splunk to receive the log file over UDP 514 as suggested.

I have no idea how to address this problem. I have done a fair bit of googling to try and find an answer or even where to start in terms of addressing the issue but no luck.

Any help in this space would be appreciated.

Thanks in advance

Anu

Tags (3)
0 Karma

asingh90
Engager

Thanks for your help anyway 🙂

0 Karma

asingh90
Engager

The problem seems to be linked to a lack of a logging function on my device.

0 Karma

amiracle
Splunk Employee
Splunk Employee

Are you still having this issue?

0 Karma

amiracle
Splunk Employee
Splunk Employee

I've been looking and have not been able to find a cause or a reason for this error message. Send me an email and I'll see if we can't troubleshoot this issue a bit further. Send me an email and I'll see what could be behind this error.

-K

0 Karma

Ayn
Legend

Sounds like a problem with your source device most of all...

asingh90
Engager

This is the error i find within wireshark. Yeah the capture in wireshark shows that the syslog message is coming in on UDP/514

0 Karma

Ayn
Legend

Where are you getting that error? Is it a syslog message coming in on UDP/514?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...