Getting Data In

syslog data sent across forwarders and multiple indexers

e82than
Communicator

I tried to do this

Send syslog data from a network device (on port: 514) to a Universal Forwarder listening on port: 514 irrespective of (ANY) host's IP -> indexer listening on port 20980 -> to another Universal Forwarder listening 20981 -> to a Syslog-NG server listening for all audit data from splunk and syslog data.

the mode of travel goes like this

__Multiple syslog data_ > UF > Indexer > UF > Syslog-NG_

the data traverses over this many system as they are in different network zones with the final Syslog-NG server there being a Vendors' component. I have ensure that the Last Syslog server is receiving all my splunkd and other splunk's logs from all the components, but i cannot get the Multiple syslog data (on port:514) to send over to the final Syslog-NG server.

What do i have to do to troubleshoot it?

I've created a similar setup which vary slightly from the top to narrow down the problem.

Multiple syslog data (on port:514) -> Syslog Indexer -> UF -> Syslog-NG_

Do note that the last Syslog-NG server is the same as the one as the top. This setup apparently is sending out all the splunkd and other splunk logs out properly, on top of that the syslog data is going over correctly.

Can anyone please show me the way forward? I thank you in advance for your kind assistance.

0 Karma

e82than
Communicator

the 2nd (similar) setup is working when sending to splunk. but the 1st example is not transmitting. Multiple syslog data as in e.g network appliances which transmits only on UDP://514 or UDP only traffic streams.

0 Karma

tskinnerivsec
Contributor

Have you run tcpdump or some other utility to verify that the last Universal Forwarder listening 20981 is actually forwarding the syslog data to your syslog endpoint?

0 Karma

Ayn
Legend

It could help if you explained more not just about the setup, but also the problem? What do you mean by multiple syslog data? What's the expected outcome and how does it not work?

0 Karma

e82than
Communicator

Help please, if anyone know?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...