Getting Data In

VM Splunk / Proxmox / Unifi

splunkman-70
New Member
Hello,
I would like my router/firewall Unifi UDM-SE send his logs to my VM (splunk+ubuntu server).
What I have done:

- on the proxmox VM no FW (during the test)
- on my VM I have two NICs, one for the management (network 205) and one for the remote logging location (splunk - network 203 -same as my udm network).
- on my VM, ufw is running, I have opened port 9997 and port 514 .
- on my UDM SE, I have forwarded the syslog to my remote splunk server (network 203).

On the Splunk server, port 514 and 9997 are listening.


Until now, no logs appear on my Splunk.
How "ufw" is dealing when running two different networks ?
How to add the second NIC (network 203) to Splunk ?

Ideas ?
 
Labels (2)
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...