Security

Netapp FAS Custom Port Setup

Dan244
New Member

Im trying to setup syslog forwarding on our FAS Netapp filers to a custom port.
I've seen instruction how to setup to the default UDP 514 port... but our splunk admin wants the logs to go to a custom port, lets say 12345. Has anyone setup their filers like this?

Thanks,

Tags (4)
0 Karma

sbrant_splunk
Splunk Employee
Splunk Employee

NetApp's Data OnTap OS uses a syslog.conf file to configure the syslog daemon. I think you can just use this syntax to forward to a different port on the remote server:

*.*     @remotehost:12345
0 Karma

Dan244
New Member

OK I've added the IP address of my Splunk server to the host file of the filer, logserv.
I'm able to resolve the server from the filer.
changed the syslog.conf file to point to logserv:12345
now i get this message on the filer:
Syslog daemon error logerror syslogd: Couldn't find address for host name "logserv:12345": Unkown resolver error.
syslogd: Restarted
As soon as I change it back to just @logserv it works ok on the standard UDP port 514

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...