Hi,
After migrated Splunk Enterprise to a new hardware, my HFs stop receiving logs over port 514/1514. It's verified these ports are open on the new HFs. The new system is receiving logs from UFs running on Windows and from Cloud-based (AWS).
What other configuration needs to be done like syslog daemon or any things else for the new HFs to receive logs being sent over port 514/1514 like F5 and other network devices?
Thank you,
Verify the ports have a listener on them. Check your firewall(s) to ensure connectivity.
If the HF moved to a new address, make sure all clients have that address.
Don't you think I need to configure the daemon syslog on the new HFs so they can receive the logs?
Yes, you absolutely need to do that.
Hi Richgalloway,
I'd like to circle back on HFs stopped receiving logs. All logs were once received well after system admin fixed the daemon log. Then last Thursday, HFs suddenly stopped receiving 9 out of 10 logs at almost same time. There is no issue with new logs. Disk space and network connection are not the cause.
Would you please share what you think?
Thank you,
"Verify the ports have a listener on them" - would you please give more details on this?
Thanks,
I use netstat -ln | grep 514
.
I used nc and received this:
ss -lnt4p | grep 514
LISTEN 0 128 :514 *:
LISTEN 0 128 127.0.0.1:51490 :
LISTEN 0 128 :1514 *:
Does that mean I have listeners on both 514 and 1514?