Getting Data In

Unable to see Symantec risk logs on heavy forwarder and indexer

mohdmikhael
Explorer

Hi, 

First off, apologies if this is the wrong forum to post this but I am stuck and need help.

I currently have a test environment set up as below.

Symantec SEPM is sending syslog to a vip load balancer which will then forward to either one of two HF. 

Flow is as follows:

Symantec SEPM > LB > HF

 

Configuration as shown below:

Symantec SEPM version 14.3 RU1 with the following syslog configuration

Syslog IP:  VIP of Load Balancer

Syslog dest port: TCP 514

Syslog Line Separator: LF

 

LB is configured to forward the logs to HF via port 9997

 

Issue: Currently, the issue is that the risk logs used to be sending over previously but seem to stop now.

 

If I have missed out anything, please let me know.

 

Any feedback is greatly appreciated. 

 

Regards,

Mikhael

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...