Getting Data In

Cymphonix Network Composer Logging Issue

afields
New Member

We are running Splunk for Windows 4.3 on Windows Server 2008 R2 x64. We are trying to pull Syslog data from a Cymphonix Network Composer EX350 unit (software version 9.2.4), via UDP port 521 (514 is in use by a WatchGuard Firewall unit).

The Cymphonix unit is pointing to the correct IP address for the Splunk server, and a Data Input on the Splunk server is configured to listen on UDP port 521. However, we are receiving no events/data from that Data Input.

I realize that this may very well be a Cymphonix issue, not a Splunk one, however I would like to cover all my bases here. Has anyone had experiencing configuring Splunk to work with a Cymphonix unit (or other such UDP unit)?

Tags (2)
0 Karma

dwaddle
SplunkTrust
SplunkTrust

Make sure port 521/udp is open on your Win64 host firewall. If not, it'll obviously be blocked and you'll never see it. Then, check with a sniffer ( http://www.wireshark.org ) to see the packets coming through. Note: Typically, wireshark will see/sniff packets before the firewall gets to filter them, which is why I suggested to check the firewall first.

dwaddle
SplunkTrust
SplunkTrust

Then, arguably ... either the Cymphonix isn't sending data on that port, or it's getting lost somewhere on the network between the two. It's hard for Splunk to index that which the network adapter never receives.

afields
New Member

Verified inbound rule in Windows Firewall allowing UDP Port 521 (although firewall is off).

WireShark capture shows no UDP packets coming from the Cymphonix IP to the Splunk IP.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...