During the conference call, we ensure the ports on the FW were opened for port 514 and that the ACLs were configured properly. The Splunk engineer did a TCPdump multiple times, but no logs showed up. We sent "send log" messages and brought an interface down then back up but still no logs being shown. At this point, we have escalated the issue.
... View more
I appreciate you taking the time out to provide this information. I just sent an email to our senior networking engineer to gather more information related to the FW rules currently in place. I will circle back once he responds to provide an update.
... View more
I don't have access to the Splunk server, it is managed by a different team. They had already done a tcpdump, but no success in locating logs from the specified host. What can I do/provide on my end regarding the switch?
... View more
I am currently in a situation where I don't have access to the actual Splunk server but have been provided the Splunk VIP to send logs.
I entered the following command on the device:
logging host x.x.x.x transport udp port 514
I am able to ping the servers that are behind the VIP. The show log commands shows that logs are being logged at the server. Is there anything else I can do on the device end to prove that logs are being sent correctly to the Splunk Server? If I have missed or done something incorrectly be let me know as well.
v/r
... View more
I'm in the process of creating a troubleshooting guide for our networking team. I would like to be able to look up event logs via Splunk Enterprise related to a specific host. The parameters for the search will allow us to view with an interface went up/down as well. How can I properly enter this request into the GUI search & reporting app?
... View more