Getting Data In

Splunk listens for syslog but no logs show up in the console

local_graph_2
New Member

I am running Splunk on Windows 7 64 bit and configured data adapters for syslog on TCP and UDP. I can see via Wireshark that syslog is making it to the main interface, Splunk is listening on 0.0.0.0:514 but I do not see any logs at all in Splunk and I verified splunkd is listening and I verified traffic is making it to the Win7 server

Tags (1)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

0.0.0.0 indicates that it's listening on all network adapters.

View solution in original post

0 Karma

local_graph_2
New Member

For Windows 7 you actually have to have the firewall on, not disabled, and create a rule allowing syslog traffic.

Took me way to long to figure that out, but hey, at least the next guy will know right?

This works now

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

0.0.0.0 indicates that it's listening on all network adapters.

0 Karma

local_graph_2
New Member

I used Wireshark on Windows 7 to see the syslog via the 192.168.x.x interface, Windows firewall is off by default as this is within a closed subnet

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Most of the time, you have to disable or configure the firewall on Windows 7.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

What did you do to ascertain that your syslog traffic was making it to the Windows 7 desktop?

0 Karma

local_graph_2
New Member

So this was my thought as well, but I do not see any logs at all in Splunk and I verified splunkd is listening and I verified traffic is making it to the Win7 server.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...