Splunk Cloud Platform

Logs not showing up in Splunk cloud

gitau_gm
Explorer

Description: We are having issues with one of our Cisco devices. We have set logging to a syslog server that should then forward to the cloud. While looking at the syslog-ng file, noticed this # udp(ip(0.0.0.0) port(514));. Removing the comment rendered several indexes idle but returning to prior state reinstated the indexes. Wondering what we could be missing. Any assistance would be great.

Labels (2)
0 Karma

gitau_gm
Explorer

gitau_gm_0-1756131382032.png

This is the current set up. Device has been on the network for a while but we don't seem to get logs to the cloud 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @gitau_gm 

Please can you provide a little more info on how you are sending this data to Splunk Cloud from syslog-ng? Has this previously worked? 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...