Security

Netapp FAS Custom Port Setup

Dan244
New Member

Im trying to setup syslog forwarding on our FAS Netapp filers to a custom port.
I've seen instruction how to setup to the default UDP 514 port... but our splunk admin wants the logs to go to a custom port, lets say 12345. Has anyone setup their filers like this?

Thanks,

Tags (4)
0 Karma

sbrant_splunk
Splunk Employee
Splunk Employee

NetApp's Data OnTap OS uses a syslog.conf file to configure the syslog daemon. I think you can just use this syntax to forward to a different port on the remote server:

*.*     @remotehost:12345
0 Karma

Dan244
New Member

OK I've added the IP address of my Splunk server to the host file of the filer, logserv.
I'm able to resolve the server from the filer.
changed the syslog.conf file to point to logserv:12345
now i get this message on the filer:
Syslog daemon error logerror syslogd: Couldn't find address for host name "logserv:12345": Unkown resolver error.
syslogd: Restarted
As soon as I change it back to just @logserv it works ok on the standard UDP port 514

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mile High Learning with Splunk University, Denver, Colorado

If Denver is known for its mile-high elevation, Splunk University is about to raise the bar on technical ...

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...