Monitoring Splunk

How can I send my SPA-1001 Syslog to Splunk?

medfordite
New Member

I have a Linskys SPA-1001 ATA adapter for VOIP. I am wanting to trap a problem where it stops receiving calls and and have enlisted the help of Splunk to see if I can get it to log the syslog files.

From the Linksys Manual:

"How do I debug my SPA? Is there a syslog?
SPA sends out debug information via syslog to a syslog server. The ports can be configured (by default the port is 514).

A. Make sure you do not have firewall running on your PC that could block port 514.
B. On the administration web server System tab, set as the IP address and port
number of your syslog server. Note that this address has to be reachable from the Linksys ATA).
C. Also, set to 3.
You do not need to change the value of the parameter.
D. To capture SIP signaling messages, under the Line tab, set to Full.
The file output is syslog..log (for the default port setting, syslog.514.log)"

I have pointed the proper fields in the ATA's pages to point to my server by utilizing my local IP of 192.168.1.140 (where Splunk Lives) . When I try to tell it to listen to UDP 514 it of course says it is in use.

My question then is would I need to tell the SPA to point to: 192.1681.1.140:514 and then Splunk will auto-digest the data being sent at this point without having to set it up to aggregate data from UDP 514? If so, this didn't seem to work.

I just need to capture the debugging data from the ATA. Unfortunately, I can't SSH or SFTP/FTP into the device even though it is an Open Device (Unlocked) as there are no options to allow logins that way to retrieve the log data itself.

Tags (1)
0 Karma

whitewool
Splunk Employee
Splunk Employee

Is splunk installed as root? In *nix land you need to have root in order to access ports below 1024..

MarioM
Motivator

well you should first try to find out in your splunk box who is listening on 514 and if this cannot be changed setup another port in Splunk then put this port in your linksys device instead of 514.

0 Karma

medfordite
New Member

I do not have anything listening on Port 514 as far as I can tell:

Port Scanning host: 192.168.1.140

 Open TCP Port:     88          kerberos
 Open TCP Port:     139         netbios-ssn
 Open TCP Port:     445         microsoft-ds
 Open TCP Port:     631         ipp
 Open TCP Port:     3689        daap
 Open TCP Port:     8000        irdmi
 Open TCP Port:     8089
 Open TCP Port:     9102        bacula-fd
 Open TCP Port:     17500
 Open TCP Port:     27997

I am using Snow Leopard on OSX as well if that helps with anything.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...