I'm new to splunk, how can I import syslog from my local computer to splunk?
- when i search it says it can be done via universal forwarder. but I want to collect my syslog logs on localhost.
-I opened the 514 udp port and created my settings on splunk. But it doesn't show up in search.
Hi @pofudukhamsi,
as you can read at https://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports you have to:
Then you'll have the logs in the index you configured in the input.
Ciao.
Giuseppe