Installation

Syslog Configuration through Splunk Web?

niha1318
New Member

Hi,

we are planning to get the Syslog data into Splunk Heavy Forwarders. They are Appliances and those are hardened linux OS.

till now i have done the following steps

I have provided the Splunk Heavy Forwarder IP to App owner, they configured the syslog on their end

I created Data inputs on HFW by giving TCP: 1024, Sourcetype, IP and created Index. (514 already being used)

I could't able able to find the data yet on splunk. is this the correct process OR am i missing anything? please let me know if i did anything wrong or if I need to add some inputs?

Thanks,

Tags (1)
0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

Do you have local firewalls blocking TCP 1024. Are you sure you are sending data to the right port?

0 Karma

niha1318
New Member

if that is the case, I hope it will through the Firewall Error. but I didn't get any firewall error.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...