Getting Data In

Syslog from Firewall issue

hartfoml
Motivator

I asked my Firewall admin to change the port for syslog to the Splunk indexer.

He changed it from 514 to 1514.

He said he made the change but I am not seeing the incoming log data.

I'm sure the indexer host firewall port is open.

Where would I go to see what data is coming in on what port?

Does splunk tag the data with the indexer connection information?

Tags (1)
0 Karma
1 Solution

hartfoml
Motivator

Used the SoS app

This app will show you

S.o.S - Splunk on Splunk > Metrics > Incoming Network Throughput

this shows the network data comeing into splunk on what ports

After checking with my lunix admin and looking in SoS I confrunted the firewall guy and they did not make the change requiered.

View solution in original post

hartfoml
Motivator

Used the SoS app

This app will show you

S.o.S - Splunk on Splunk > Metrics > Incoming Network Throughput

this shows the network data comeing into splunk on what ports

After checking with my lunix admin and looking in SoS I confrunted the firewall guy and they did not make the change requiered.

FunPolice
Path Finder

The low-impact way would be to get IP accounting or netflow data from any routers or switches between the firewall and your indexer.

Otherwise you could install packet capture software (Wireshark or Microsoft Network Monitor, for example) on your indexer and capture all of the traffic that's hitting its network port.

If you can get a SPAN port set up (it sends a copy of all traffic heading for one switch port to a second port) then you can install the packet capture software on any machine and avoid touching your indexer.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...