Installation

Syslog Configuration through Splunk Web?

niha1318
New Member

Hi,

we are planning to get the Syslog data into Splunk Heavy Forwarders. They are Appliances and those are hardened linux OS.

till now i have done the following steps

I have provided the Splunk Heavy Forwarder IP to App owner, they configured the syslog on their end

I created Data inputs on HFW by giving TCP: 1024, Sourcetype, IP and created Index. (514 already being used)

I could't able able to find the data yet on splunk. is this the correct process OR am i missing anything? please let me know if i did anything wrong or if I need to add some inputs?

Thanks,

Tags (1)
0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

Do you have local firewalls blocking TCP 1024. Are you sure you are sending data to the right port?

0 Karma

niha1318
New Member

if that is the case, I hope it will through the Firewall Error. but I didn't get any firewall error.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...