Security

Netapp FAS Custom Port Setup

Dan244
New Member

Im trying to setup syslog forwarding on our FAS Netapp filers to a custom port.
I've seen instruction how to setup to the default UDP 514 port... but our splunk admin wants the logs to go to a custom port, lets say 12345. Has anyone setup their filers like this?

Thanks,

Tags (4)
0 Karma

sbrant_splunk
Splunk Employee
Splunk Employee

NetApp's Data OnTap OS uses a syslog.conf file to configure the syslog daemon. I think you can just use this syntax to forward to a different port on the remote server:

*.*     @remotehost:12345
0 Karma

Dan244
New Member

OK I've added the IP address of my Splunk server to the host file of the filer, logserv.
I'm able to resolve the server from the filer.
changed the syslog.conf file to point to logserv:12345
now i get this message on the filer:
Syslog daemon error logerror syslogd: Couldn't find address for host name "logserv:12345": Unkown resolver error.
syslogd: Restarted
As soon as I change it back to just @logserv it works ok on the standard UDP port 514

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...