Hello guys,
I am trying to forward the logs of Aruba wireless controllers into Splunk, but I am not able see the logs in Splunk. I am forwarding the logs to the Splunk server via UDP/514 port. Is there anything else that needs to be configured in the Splunk server like input files etc?
Are you listening on udp/514? Check Settings > Data Inputs > UDP
for a port 514. If it is not there, add it, and then check the results.
For a great tutorial on using syslog with Splunk, check out this article. http://www.georgestarcher.com/splunk-success-with-syslog/