Monitoring Splunk

Polycom Video Infrastructure - Monitoring with Splunk

ashishsinghal
New Member

Any success story for this integration ? Right now i am stuck as i am trying to forward Polycom DMA syslogs to splunk and as Polycom uses UDP 514 & as this is a reserve port Splunk can't accept logs from Polcyom. Please advise, if there are other ways.

I am focusing on Quality Monitoring, end point registration & MCUs utilization.

Tags (1)
0 Karma

tiagofbmm
Influencer

You can send logs to Splunk and configure any available port to listen to those syslog messages:

[tcp://<remote server>:<port>]
* Configures the input to listen on a specific TCP network port.

[udp://<remote server>:<port>]
* Configures the input to listen on a specific UDP network port.

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf

Usually sending syslog directly to Splunk is not a best practice but you could instead use an intermediate Syslog-NG or Rsyslog to write it to disk, and have a Splunk UF monitoring those files.

If your Polycom can send HTTP data, you can also enabel HEC on Splunk Indexers and listen to that stream of data directly into Splunk:

https://docs.splunk.com/Documentation/Splunk/7.3.0/Data/UsetheHTTPEventCollector

0 Karma
Get Updates on the Splunk Community!

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...