Getting Data In

VM Splunk / Proxmox / Unifi

splunkman-70
New Member
Hello,
I would like my router/firewall Unifi UDM-SE send his logs to my VM (splunk+ubuntu server).
What I have done:

- on the proxmox VM no FW (during the test)
- on my VM I have two NICs, one for the management (network 205) and one for the remote logging location (splunk - network 203 -same as my udm network).
- on my VM, ufw is running, I have opened port 9997 and port 514 .
- on my UDM SE, I have forwarded the syslog to my remote splunk server (network 203).

On the Splunk server, port 514 and 9997 are listening.


Until now, no logs appear on my Splunk.
How "ufw" is dealing when running two different networks ?
How to add the second NIC (network 203) to Splunk ?

Ideas ?
 
Labels (2)
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...