Getting Data In

Unable to see Symantec risk logs on heavy forwarder and indexer

mohdmikhael
Explorer

Hi, 

First off, apologies if this is the wrong forum to post this but I am stuck and need help.

I currently have a test environment set up as below.

Symantec SEPM is sending syslog to a vip load balancer which will then forward to either one of two HF. 

Flow is as follows:

Symantec SEPM > LB > HF

 

Configuration as shown below:

Symantec SEPM version 14.3 RU1 with the following syslog configuration

Syslog IP:  VIP of Load Balancer

Syslog dest port: TCP 514

Syslog Line Separator: LF

 

LB is configured to forward the logs to HF via port 9997

 

Issue: Currently, the issue is that the risk logs used to be sending over previously but seem to stop now.

 

If I have missed out anything, please let me know.

 

Any feedback is greatly appreciated. 

 

Regards,

Mikhael

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...