Security

Monitor Cyberoam 35iNG

nilesh8
New Member

Hi All,

How to configure splunk 5.0 to monitor Cyberoam 35iNG firewall.

Tags (2)
0 Karma

rturk
Builder

Hi nilesh8.

I'm not familiar with that particular firewall, but I'm assuming that it is capable of sending Syslog messages.

You can configure Splunk to accept Syslog messages by following the steps in this link: http://docs.splunk.com/Documentation/Splunk/5.0.4/Data/SyslogUDP

Hope this helps 🙂

0 Karma

nilesh8
New Member

I have found following entries in splunk log
08-26-2013 04:22:05.656 -0700 INFO TcpInputConfig - performing DNS lookup on 192.168.2.1

Also i tried it to configure via SNMP and found below log
CarrierError: bind() for (u'192.168.2.1', 162) failed: [Errno 10049] The requested address is not valid in its context

0 Karma

rturk
Builder

My only other suggestions at this point would be to narrow down the possible cause:
- Redirect a device/server with a known-good syslog generation at Splunk
- Point your firewall at a known/good syslog collector
- Look at the event in $SPLUNK_HOME/var/log/splunk/splunkd.log to see any potential issues

Everything you've mentioned indicates you've set it up correctly, so it's time for troubleshooting now 🙂

0 Karma

nilesh8
New Member

I have configured it via tcp and udp port 514 still i am waiting for logs.

0 Karma

nilesh8
New Member

I have configured it with TCP 514 only
TCP port = 514
Source type = syslog
Status = Enabled

0 Karma

rturk
Builder

Ahhh one other point I forgot to mention, have you confirmed that Splunk is set up to receive TCP 514?
- Manager > Data Inputs > TCP > Add New
You might want to do the same for UDP just to be sure.

0 Karma

nilesh8
New Member

I have configured it by TCP port and also disabled server firewall but still not see any logs on splunk

0 Karma

rturk
Builder

A few things I'd check:
- Ensure Syslog is being sent by TCP not UDP
- Temporarily disable the server firewall on the Splunk server to see whether that's a factor

0 Karma

nilesh8
New Member

Hi Turk,
Thanks for reply. I have configured it via syslog udp port 514. But i am not able to see any logs in splunk also not show the connection in 'netstat' command.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...