Security

Netapp FAS Custom Port Setup

Dan244
New Member

Im trying to setup syslog forwarding on our FAS Netapp filers to a custom port.
I've seen instruction how to setup to the default UDP 514 port... but our splunk admin wants the logs to go to a custom port, lets say 12345. Has anyone setup their filers like this?

Thanks,

Tags (4)
0 Karma

sbrant_splunk
Splunk Employee
Splunk Employee

NetApp's Data OnTap OS uses a syslog.conf file to configure the syslog daemon. I think you can just use this syntax to forward to a different port on the remote server:

*.*     @remotehost:12345
0 Karma

Dan244
New Member

OK I've added the IP address of my Splunk server to the host file of the filer, logserv.
I'm able to resolve the server from the filer.
changed the syslog.conf file to point to logserv:12345
now i get this message on the filer:
Syslog daemon error logerror syslogd: Couldn't find address for host name "logserv:12345": Unkown resolver error.
syslogd: Restarted
As soon as I change it back to just @logserv it works ok on the standard UDP port 514

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...