Description: We are having issues with one of our Cisco devices. We have set logging to a syslog server that should then forward to the cloud. While looking at the syslog-ng file, noticed this # udp(ip(0.0.0.0) port(514));. Removing the comment rendered several indexes idle but returning to prior state reinstated the indexes. Wondering what we could be missing. Any assistance would be great.
This is the current set up. Device has been on the network for a while but we don't seem to get logs to the cloud
Hi @gitau_gm
Please can you provide a little more info on how you are sending this data to Splunk Cloud from syslog-ng? Has this previously worked?
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing