Getting Data In

VM Splunk / Proxmox / Unifi

splunkman-70
New Member
Hello,
I would like my router/firewall Unifi UDM-SE send his logs to my VM (splunk+ubuntu server).
What I have done:

- on the proxmox VM no FW (during the test)
- on my VM I have two NICs, one for the management (network 205) and one for the remote logging location (splunk - network 203 -same as my udm network).
- on my VM, ufw is running, I have opened port 9997 and port 514 .
- on my UDM SE, I have forwarded the syslog to my remote splunk server (network 203).

On the Splunk server, port 514 and 9997 are listening.


Until now, no logs appear on my Splunk.
How "ufw" is dealing when running two different networks ?
How to add the second NIC (network 203) to Splunk ?

Ideas ?
 
Labels (2)
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...