Getting Data In

sending syslog from tplink

imontanoisoft
Explorer

I am sending syslog from tplink switch but I can not see it in the forwarder management, however I can see the logs in the app search : source="udp:514" sourcetype="syslog"

Tags (1)
0 Karma
1 Solution

acharlieh
Influencer

Forwarder management is for managing Splunk Forwarders with a feature known as Deployment server.

Devices like switches that send logs using syslog protocols would never show up under forwarder management, nor would forwarders whose configuration is managed outside of Deployment server. (such as using Chef or other automation).

You might be interested in this documentation: https://docs.splunk.com/Documentation/Splunk/7.2.4/Updating/Aboutdeploymentserver

View solution in original post

0 Karma

acharlieh
Influencer

Forwarder management is for managing Splunk Forwarders with a feature known as Deployment server.

Devices like switches that send logs using syslog protocols would never show up under forwarder management, nor would forwarders whose configuration is managed outside of Deployment server. (such as using Chef or other automation).

You might be interested in this documentation: https://docs.splunk.com/Documentation/Splunk/7.2.4/Updating/Aboutdeploymentserver

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...