Getting Data In

Why are new UDP data inputs for multiple hosts initially disabled after creation?

xxyz
Explorer

Creating new UDP Data Inputs for received syslog data from specific hosts to go to a specific Index. After creating the data input with multiple hosts (comma delimited) the status is initially disabled. I have no problem enabling afterwards, but wondering if multiple hosts aren't allowed and that is why it is disabled or is it just a precaution?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Yeah, inputs.conf

0 Karma

xxyz
Explorer

so i added them all in. no problems. they show up in the gui just fine. however...

when i set a stanza to collect all syslog traffic and direct it to index 'syslog', it doesn't show in the gui. so will this work even though it's not showing?

[udp:514]
index = syslog
sourcetype = syslog
connection_host = ip

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Did you bump Splunk after making the change in the .conf file? Either by restarting or by hitting this URL:

http://your_host:8000/en-US/debug/refresh?entity=admin/conf-inputs
0 Karma

xxyz
Explorer

interesting. normally configurations adding in the gui update conf files under local, but these additions do not.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

All UI settings must appear under local directories, else they would be lost on an upgrade of Splunk.
Make sure you've not just checked the wrong app and keep system/local in mind.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

How are you creating the inputs?

0 Karma

xxyz
Explorer

through the gui: settings > data inputs > > udp > new

is there a conf to do this?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Drivers: How We're Streaming Real-Time F1 Telemetry Directly into Splunk ...

Data Drivers: Every Lap Tells a Story The Spectacle Two F1 racing sims go head-to-head on the .conf26 show ...

Data Management Digest – July 2026

  Welcome to the July 2026 edition of Data Management Digest! As your trusted partner in data innovation, the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...