Installation

Syslog Configuration through Splunk Web?

niha1318
New Member

Hi,

we are planning to get the Syslog data into Splunk Heavy Forwarders. They are Appliances and those are hardened linux OS.

till now i have done the following steps

I have provided the Splunk Heavy Forwarder IP to App owner, they configured the syslog on their end

I created Data inputs on HFW by giving TCP: 1024, Sourcetype, IP and created Index. (514 already being used)

I could't able able to find the data yet on splunk. is this the correct process OR am i missing anything? please let me know if i did anything wrong or if I need to add some inputs?

Thanks,

Tags (1)
0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

Do you have local firewalls blocking TCP 1024. Are you sure you are sending data to the right port?

0 Karma

niha1318
New Member

if that is the case, I hope it will through the Firewall Error. but I didn't get any firewall error.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...