Hi there! Seems like your test logs are working, but real-world ones aren't showing up. Here's what might be happening: Filter Frenzy: Double-check your Splunk filters. You might have one accidentally hiding those juicy UPS logs. Severity Sleight of Hand: Splunk might not be ingesting lower severity logs by default. Try adjusting your search filters or source type settings to include them. Port Mismatch: Make sure your Splunk server is listening on port 514 for UDP traffic. A quick netstat check can confirm this. If none of these work, give your Splunk logs a good scan for error messages related to UPS data. They might offer more specific clues. ~ If the reply helps, a Karma upvote would be appreciated
... View more