Splunk Cloud Platform

Issue with Data Inputs TCP/UDP setting

asif99usa
New Member

Splunk Connect for Syslog
This is Splunk’s preferred method of ingesting high volumes of data. Details can be located here →
https://splunk-connect-for-syslog.readthedocs.io/en/latest/
TCP Data Input
Navigate to Settings -> Data Inputs -> TCP (Add new)
This brings you to following screen. In this step, we will configure Splunk to listen on TCP using
port 514. NSS only supports TCP, but the destination port is configurable. Most administrators use
port “514” as it is the default port for UDP based syslog. After configuring SIEM port, click next

 

We're following the above step but not able to find TCP / UDP  configure the port to synced with Zscaler NSS. I'm logging in Splunk Cloud portal  as trial member. Could it be restriction/privilege to my trail account ?  Please advice 

 

Thanks

Asif   

 

 

asif99usa_0-1638466258065.png

 

Labels (1)
0 Karma

Roy_9
Motivator

You can configure this on an On premise Heavy forwarder and connect this HF to Splunk Cloud.

As Rich said below, Splunk cloud(SH/IDM) doesn't support TCP/UDP streams as it will be risky and might blew up the license.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk Cloud does not support TCP/UDP inputs.  They're not used with SC4S, anyway.  Use a HEC input.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...