Security

Why is the index not capturing UDP PortTraffic data?

charleswmiller
New Member

Within Splunk, we created two UDP ports. We are able to see traffic using Wireshark, however, the Splunk index is not populating.

Not using Splunk Forwarders - Listing for UDP traffic on two UDP defined Ports

Is there additional configuration necessary?

0 Karma

adonio
Ultra Champion

please share your inputs.conf also, try and search index=* if oyu didnt define index on your inputs, it will go to the default index. lastly, verify your UDP sources has Splunk IP and relevant port configured as target

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...