All Apps and Add-ons

data type other than sc4s:events and sc4s:fallback not getting ingested using SC4S (Multiple network interface)

nvij_splunk
Splunk Employee
Splunk Employee

data is coming in only for source types sc4s: events and sc4s: fallback. There are multiple compatible devices like (cisco ASA) set up to send data via UDP 514 at the server and nothing is being sent to Splunk. Does anyone have any ideas on how to troubleshoot this? (podman with systemd)

There are 2 network interfaces

Labels (1)
0 Karma

nvij_splunk
Splunk Employee
Splunk Employee
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...