Splunk Search

How to check whether splunk is receiving logs from particular IP

splunklearner
Communicator

Hi Guys,

Syslog is sent to forwarder IP through TCP 9523 port. I am unable to receive those syslog in forwarder or indexer.

How to check whether syslog is received in forwarder ?

How to receive those syslog in indexer?

Getting those logs from network device.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@splunklearner wrote:

I am unable to receive those syslog in forwarder or indexer.

Why not?  What errors do you see?

Sending syslog directly to a Splunk process is not good practice.  Syslog events should be sent to a dedicated syslog server (like rsyslog or syslog-ng) and saved to disk.  Then have a Splunk Universal Forwarder monitor those disk files.

---
If this reply helps you, Karma would be appreciated.

splunklearner
Communicator

Hi @richgalloway ,

Yes we have a dedicated syslog ng server and UF in place to forward it to indexer. 

But we are not receiving logs.. how can I troubleshoot this issue? To check whether issue is from splunk end or requestor end?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check the whole path from sender to receiver to Splunk.  Verify network connectivity at each step.

Verify the syslog server is writing data to disk.  Confirm Splunk is monitoring those files and has read access to them.  Check splunkd.log to see if there are messages about the files.

Check the indexer for internal log files from the forwarder.  If they are not present then you have a connectivity problem between the forwarder and indexer (at least).

When searching for data, use a wide time window that includes the future (earliest=-2d latest=+2d) in case the events are not onboarded properly.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...