Getting Data In

Printer logs

aleksandarrrc
Explorer

Hello,
Is there any manual, where i can see how to collect print logs from remote machine?
The printer from which i have to collect event logs is Lexmark X464 de.

Edit:
I configured Lexmark to send audit logs, to ip of the machine where Splunk is installed. I also configured syslog UDP port in SplunkWeb but it still don't collect event logs from printer.
Is there at least any command in cmd to test connections between printer and Splunk.
Thanks in advance.

Last Edit:
Sry for the question, problem solved!

Tags (1)
0 Karma

tskinnerivsec
Contributor

I know you solved your issue, but the best way to test your connection between the printer and the splunk instance would be to use tcpdump if it is a linux system (tcpdump -i eth0 (or whatever your interface name is) port 514 (or whatever port you are sending syslog to). If splunk was running on a windows computer, you could use a tool like wireshark to listen for the syslog traffic. If you see the traffic and still didn't see it in your instance, I would check the host based firewall. Anti-virus shouldn't have anything to do with it.

0 Karma

Drainy
Champion

In this case the packets were still arriving on the computer but a software firewall was playing up after a botched uninstall and was still blocking them, there was quite a bit of troubleshooting yesterday in the IRC channel 🙂

0 Karma

aleksandarrrc
Explorer

The solution was to make sure, that both firewall and Antivirus are turned off.

0 Karma

aleksandarrrc
Explorer

That is certainly, more precise answer 🙂

Drainy
Champion

Well, I wouldn't neccessarily say turn off the antivirus, just be sure that it isn't interfering with Splunks operation and that any built in firewall has exceptions for your ports. As I understand it you just had a botched install/uninstall which isn't quite the same as needing both off 🙂

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...