Hi Guys,
Syslog is sent to forwarder IP through TCP 9523 port. I am unable to receive those syslog in forwarder or indexer.
How to check whether syslog is received in forwarder ?
How to receive those syslog in indexer?
Getting those logs from network device.
@splunklearner wrote:I am unable to receive those syslog in forwarder or indexer.
Why not? What errors do you see?
Sending syslog directly to a Splunk process is not good practice. Syslog events should be sent to a dedicated syslog server (like rsyslog or syslog-ng) and saved to disk. Then have a Splunk Universal Forwarder monitor those disk files.
Hi @richgalloway ,
Yes we have a dedicated syslog ng server and UF in place to forward it to indexer.
But we are not receiving logs.. how can I troubleshoot this issue? To check whether issue is from splunk end or requestor end?
Check the whole path from sender to receiver to Splunk. Verify network connectivity at each step.
Verify the syslog server is writing data to disk. Confirm Splunk is monitoring those files and has read access to them. Check splunkd.log to see if there are messages about the files.
Check the indexer for internal log files from the forwarder. If they are not present then you have a connectivity problem between the forwarder and indexer (at least).
When searching for data, use a wide time window that includes the future (earliest=-2d latest=+2d) in case the events are not onboarded properly.