I've got splunk working properly on a CentOS 6.5 box. I have another CentOS box client, and I can telnet to the port 8001 on the splunk box and send events, and they show up in splunk. But rsyslog events don't ever show up in splunk.
Here's the only modification that I made to the end of /etc/rsyslog.conf:
# remote host is: name/ip:port, e.g. 192.168.0.1:514, port optional
*.* @@splunk.mydomain.com:8001
And here's what happens when I telnet to it:
[root@app ~]# telnet splunk.mydomain.com 8001
Trying 10.1.3.203...
Connected to splunk.mydomain.com.
Escape character is '^]'.
hi
^]
telnet> quit
Connection closed.
And that results in a "hi" event showing up in splunk.
Now, if I log something from the command line, it shows up in /var/log/messages:
[root@app ~]# tail /var/log/messages -n 1
Mar 12 16:00:13 app test: WHATEVER BRO
But I get nothing new in splunk, and a search for "WHATEVER BRO" turns up nothing... What am I missing?
Thanks!
... View more