Hi Frnd,
See here you have just mentioned the ipaddress of the other host in the syslog.conf file in which where your all logs that listening to the port 514 to be forwarded tell me that have you installed and configured the splunk on the 192.168.1.1 server?.
inform me whether above my comments gave you an idea.
Regards,
Aravinth
... View more