Hi All,
I'm just getting started so this is probably going to be an easy one.
I have Splunk light and have setup PFSense logs to output UDP Port 514 and setup a Splunk Monitor to gather the data (with syslog Source Type), however, when I look in the search the Host is not listed although it is visible in Data Inputs.
I did think that may be it is not visible until the data is detected/collected but I can see with Wire shark that PFsence is sending the data.
What am I doing wrong?
Thanks all
... View more