Hi everyone,
just started with splunk. I installed it on a windows pro, but cant understand how it works : i d like receive my syslog from my Netasq u70 (syslog on 514 udp port activated and tested : it works ) on the splunk. So i tried to setting up the "forwarding and receiving". In the "receiving part" i wrote the 514 port but its doesnt work, its seems not receving the syslog from my Netasq.
So i am wrong ? Whats the procedure to config it ?
Thx you very much
You shouldn't configure a receiving port, you should configure a data input port. Receiving ports are reserved for forwarded traffic between Splunk instances.
No one 😞 ?