Security

Monitor Cyberoam 35iNG

nilesh8
New Member

Hi All,

How to configure splunk 5.0 to monitor Cyberoam 35iNG firewall.

Tags (2)
0 Karma

rturk
Builder

Hi nilesh8.

I'm not familiar with that particular firewall, but I'm assuming that it is capable of sending Syslog messages.

You can configure Splunk to accept Syslog messages by following the steps in this link: http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/SyslogUDP

Hope this helps 🙂

0 Karma

nilesh8
New Member

I have found following entries in splunk log
08-26-2013 04:22:05.656 -0700 INFO TcpInputConfig - performing DNS lookup on 192.168.2.1

Also i tried it to configure via SNMP and found below log
CarrierError: bind() for (u'192.168.2.1', 162) failed: [Errno 10049] The requested address is not valid in its context

0 Karma

rturk
Builder

My only other suggestions at this point would be to narrow down the possible cause:
- Redirect a device/server with a known-good syslog generation at Splunk
- Point your firewall at a known/good syslog collector
- Look at the event in $SPLUNK_HOME/var/log/splunk/splunkd.log to see any potential issues

Everything you've mentioned indicates you've set it up correctly, so it's time for troubleshooting now 🙂

0 Karma

nilesh8
New Member

I have configured it via tcp and udp port 514 still i am waiting for logs.

0 Karma

nilesh8
New Member

I have configured it with TCP 514 only
TCP port = 514
Source type = syslog
Status = Enabled

0 Karma

rturk
Builder

Ahhh one other point I forgot to mention, have you confirmed that Splunk is set up to receive TCP 514?
- Manager > Data Inputs > TCP > Add New
You might want to do the same for UDP just to be sure.

0 Karma

nilesh8
New Member

I have configured it by TCP port and also disabled server firewall but still not see any logs on splunk

0 Karma

rturk
Builder

A few things I'd check:
- Ensure Syslog is being sent by TCP not UDP
- Temporarily disable the server firewall on the Splunk server to see whether that's a factor

0 Karma

nilesh8
New Member

Hi Turk,
Thanks for reply. I have configured it via syslog udp port 514. But i am not able to see any logs in splunk also not show the connection in 'netstat' command.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...