Getting Data In

Splunk listens for syslog but no logs show up in the console

local_graph_2
New Member

I am running Splunk on Windows 7 64 bit and configured data adapters for syslog on TCP and UDP. I can see via Wireshark that syslog is making it to the main interface, Splunk is listening on 0.0.0.0:514 but I do not see any logs at all in Splunk and I verified splunkd is listening and I verified traffic is making it to the Win7 server

Tags (1)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

0.0.0.0 indicates that it's listening on all network adapters.

View solution in original post

0 Karma

local_graph_2
New Member

For Windows 7 you actually have to have the firewall on, not disabled, and create a rule allowing syslog traffic.

Took me way to long to figure that out, but hey, at least the next guy will know right?

This works now

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

0.0.0.0 indicates that it's listening on all network adapters.

0 Karma

local_graph_2
New Member

I used Wireshark on Windows 7 to see the syslog via the 192.168.x.x interface, Windows firewall is off by default as this is within a closed subnet

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Most of the time, you have to disable or configure the firewall on Windows 7.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

What did you do to ascertain that your syslog traffic was making it to the Windows 7 desktop?

0 Karma

local_graph_2
New Member

So this was my thought as well, but I do not see any logs at all in Splunk and I verified splunkd is listening and I verified traffic is making it to the Win7 server.

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...