Getting Data In

syslog is not working

carcab
New Member

I configure syslog on my cisco router and switch, and I am no receiving any data into my splunk server. Yes I enable syslog on my devices and i enable port 514 on splunk server

thanks

Tags (1)
0 Karma

carcab
New Member

I think the problem that I have is on my cisco devices configuration. If anyone can help me with this configuration, I will thank you.

I am using windows 7 for Splunk server.

I enable TCP and UDP in the Splunk configuration.

On my cisco devices I configure them with this commands: #logging 192.168.1.7 this address is splunk server.

On Splunk server: - Data Inputs UDP ( Listen on a UDP port for incoming data, e.g. syslog).
-New
-UDP port 514
-Set source type: From list
-Select source type from list: Syslog
-Save.
-What level of logging did you choose for your cisco devices? How to change the level of logging for you cisco device?
-Except Splunk is running as root/privileged ? How to run splunk as a root or privileged?

0 Karma

Ayn
Legend

Is that really the correct syntax on your Cisco device? Shouldn't it be "logging host 192.168.1.7"?

0 Karma

yannK
Splunk Employee
Splunk Employee
0 Karma

seunomosowon
Communicator

Except Splunk is running as root/privileged user (not recommended), It would not listen on ports below 1024. Syslog uses UDP 514. You could also have your iptables redirect port 514 to a higher port which splunk can listen on.

0 Karma

Voltaire
Communicator

Did you enable TCP or UDP in the Splunk configuration? What level of logging did you choose for your cisco devices? what OS are you using for your splunk server?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...