Hello. We are currently running Splunk 7.0.2 on Windows Server 2012 r2 and are attempting to send syslog data from our Barracuda Web Content Filter to Splunk for indexing.
I have setup the syslogging on the Barracuda to send to the IP address of the Splunk server at TCP port 514.
I have ensured that Splunk is listening to TCP port 514 via the GUI and also through netstat.
My index is still sitting at 0.00mb and no data appears to be coming in.
There are no firewalls between the Splunk server and the WCF. Splunk is running under the local system account in Windows.
Any thoughts? Thank you.
... View more