Installation

Syslog Configuration through Splunk Web?

niha1318
New Member

Hi,

we are planning to get the Syslog data into Splunk Heavy Forwarders. They are Appliances and those are hardened linux OS.

till now i have done the following steps

I have provided the Splunk Heavy Forwarder IP to App owner, they configured the syslog on their end

I created Data inputs on HFW by giving TCP: 1024, Sourcetype, IP and created Index. (514 already being used)

I could't able able to find the data yet on splunk. is this the correct process OR am i missing anything? please let me know if i did anything wrong or if I need to add some inputs?

Thanks,

Tags (1)
0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

Do you have local firewalls blocking TCP 1024. Are you sure you are sending data to the right port?

0 Karma

niha1318
New Member

if that is the case, I hope it will through the Firewall Error. but I didn't get any firewall error.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...