Splunk Cloud Platform

Issue with Data Inputs TCP/UDP setting

asif99usa
New Member

Splunk Connect for Syslog
This is Splunk’s preferred method of ingesting high volumes of data. Details can be located here →
https://splunk-connect-for-syslog.readthedocs.io/en/latest/
TCP Data Input
Navigate to Settings -> Data Inputs -> TCP (Add new)
This brings you to following screen. In this step, we will configure Splunk to listen on TCP using
port 514. NSS only supports TCP, but the destination port is configurable. Most administrators use
port “514” as it is the default port for UDP based syslog. After configuring SIEM port, click next

 

We're following the above step but not able to find TCP / UDP  configure the port to synced with Zscaler NSS. I'm logging in Splunk Cloud portal  as trial member. Could it be restriction/privilege to my trail account ?  Please advice 

 

Thanks

Asif   

 

 

asif99usa_0-1638466258065.png

 

Labels (1)
0 Karma

Roy_9
Motivator

You can configure this on an On premise Heavy forwarder and connect this HF to Splunk Cloud.

As Rich said below, Splunk cloud(SH/IDM) doesn't support TCP/UDP streams as it will be risky and might blew up the license.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk Cloud does not support TCP/UDP inputs.  They're not used with SC4S, anyway.  Use a HEC input.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...