Getting Data In

syslog is not working

carcab
New Member

I configure syslog on my cisco router and switch, and I am no receiving any data into my splunk server. Yes I enable syslog on my devices and i enable port 514 on splunk server

thanks

Tags (1)
0 Karma

carcab
New Member

I think the problem that I have is on my cisco devices configuration. If anyone can help me with this configuration, I will thank you.

I am using windows 7 for Splunk server.

I enable TCP and UDP in the Splunk configuration.

On my cisco devices I configure them with this commands: #logging 192.168.1.7 this address is splunk server.

On Splunk server: - Data Inputs UDP ( Listen on a UDP port for incoming data, e.g. syslog).
-New
-UDP port 514
-Set source type: From list
-Select source type from list: Syslog
-Save.
-What level of logging did you choose for your cisco devices? How to change the level of logging for you cisco device?
-Except Splunk is running as root/privileged ? How to run splunk as a root or privileged?

0 Karma

Ayn
Legend

Is that really the correct syntax on your Cisco device? Shouldn't it be "logging host 192.168.1.7"?

0 Karma

yannK
Splunk Employee
Splunk Employee
0 Karma

seunomosowon
Communicator

Except Splunk is running as root/privileged user (not recommended), It would not listen on ports below 1024. Syslog uses UDP 514. You could also have your iptables redirect port 514 to a higher port which splunk can listen on.

0 Karma

Voltaire
Communicator

Did you enable TCP or UDP in the Splunk configuration? What level of logging did you choose for your cisco devices? what OS are you using for your splunk server?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...