Splunk Cloud Platform

Logs not showing up in Splunk cloud

gitau_gm
Explorer

Description: We are having issues with one of our Cisco devices. We have set logging to a syslog server that should then forward to the cloud. While looking at the syslog-ng file, noticed this # udp(ip(0.0.0.0) port(514));. Removing the comment rendered several indexes idle but returning to prior state reinstated the indexes. Wondering what we could be missing. Any assistance would be great.

Labels (2)
0 Karma

gitau_gm
Explorer

gitau_gm_0-1756131382032.png

This is the current set up. Device has been on the network for a while but we don't seem to get logs to the cloud 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @gitau_gm 

Please can you provide a little more info on how you are sending this data to Splunk Cloud from syslog-ng? Has this previously worked? 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...