HI @vsingla1 ,
Thanks for your response. All set in our environment. But one small thing is missing.
We have installed Splunk Enterprise& Splunk UF on same Linux server. And configured in our firewall to send the syslogs to same Linux server. Our Splunk indexer is showing the logs of local Linux server logs fine, but unable to display/index the firewalled syslogs. Syslogs from firewall are coming to the device we have done a packet capture test on the server, it showed all the incoming syslog traffic to Linux server.
Just a small step away from displaying those logs. but unable to find it. Need support.
... View more