Deployment Architecture

universal forwarder on windows not forwarding SYSLOG

mikefoti
Communicator

So far I have been unable to get the universal forwarder to forward any events via syslog.

After initial install, using wireshark, I did see TCP being sent out. But since I only want to foward via syslog, using UDP port 514, I edited \local\outputs.conf so it includes only these lines:

[syslog]
defaultGroup = PrdIndexer_udp514

[syslog:PrdIndexer_udp514]
disabled = false
server = 123.456.789.123:514

I restarted the windows "SplunkForwader" service and still see no UDP/514 leaving the box.

Tags (1)
0 Karma
1 Solution

araitz
Splunk Employee
Splunk Employee

araitz
Splunk Employee
Splunk Employee

I think you are overlooking this:

http://splunk-base.splunk.com/answers/28991/universal-forwarder-send-syslog-to-a-thrid-party/29181

"Universal Forwarders do not Forward Syslog."

0 Karma

mikefoti
Communicator

Thanks araitz... I re-read that link and do see one thing I overlooked before... but not sure if its significant.

This statement...
Note: If you have defined multiple event types for syslog data, the event type names must all include the string "syslog".

I believe the only time might have affected "event types" would have been during the initial install when I selected to monitor/forward events from the local windows System eventlog. So, do I need to re-specify what needs monitored and forwarded so that the syslog forwarding engine becomes aware?

0 Karma

mikefoti
Communicator

Only 8 views and 0 answers!?!?!

I
m not sure if my question is too difficult, lacks enough detail or maybe has been asked/answered too many times.

Anybody have any advice?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...