I configured my application to log to Splunk, I see the package arriving in wirehark but it does not appear in wireshark.
What setting have I forgotten? Or is it missing
Hi toledotiago,
the input you opened is Splunk-TCP input to receive data from a Splunk Universal Forwarder in Splunk’s internal format, not any arbitrary tcp source.
Take a look at https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/Monitornetworkports for the tcp/udp input you are looking for.
If you are dealing with syslog i highly recommend this blog:
http://www.georgestarcher.com/splunk-success-with-syslog/
Sincerely
hgrow