Getting Data In

syslog is not working

carcab
New Member

I configure syslog on my cisco router and switch, and I am no receiving any data into my splunk server. Yes I enable syslog on my devices and i enable port 514 on splunk server

thanks

Tags (1)
0 Karma

carcab
New Member

I think the problem that I have is on my cisco devices configuration. If anyone can help me with this configuration, I will thank you.

I am using windows 7 for Splunk server.

I enable TCP and UDP in the Splunk configuration.

On my cisco devices I configure them with this commands: #logging 192.168.1.7 this address is splunk server.

On Splunk server: - Data Inputs UDP ( Listen on a UDP port for incoming data, e.g. syslog).
-New
-UDP port 514
-Set source type: From list
-Select source type from list: Syslog
-Save.
-What level of logging did you choose for your cisco devices? How to change the level of logging for you cisco device?
-Except Splunk is running as root/privileged ? How to run splunk as a root or privileged?

0 Karma

Ayn
Legend

Is that really the correct syntax on your Cisco device? Shouldn't it be "logging host 192.168.1.7"?

0 Karma

yannK
Splunk Employee
Splunk Employee
0 Karma

seunomosowon
Communicator

Except Splunk is running as root/privileged user (not recommended), It would not listen on ports below 1024. Syslog uses UDP 514. You could also have your iptables redirect port 514 to a higher port which splunk can listen on.

0 Karma

Voltaire
Communicator

Did you enable TCP or UDP in the Splunk configuration? What level of logging did you choose for your cisco devices? what OS are you using for your splunk server?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...