Getting Data In

Not getting data from Heavy Forwarder

munisankar
New Member

Hello,
Recently we have deployed the Splunk Enterprise.
Our moto is to monitor Wi-Fi usage, our Wi-Fi devices sending log data to syslog server, in syslog I have installed HF and configured all required settings but unfortunately am not seeing any data flow to splunk indexer.

Configuration:
Heavy Forwarder
Outputs.conf - configuration

[tcpout:group1]
server=X.X.X.X:9997
[tcpout]
indexAndForward=true

inputs.conf - configuration

[monitor:///var/log/messages]
sourcetype= cisco:ise:syslog

Splunk Enterprise
Enabled receiving in port no - 9997

inputs.conf - configuration
[default]
host = splunk server hostname
[splunktcp://9997]
disabled = 0

Firewall been adjusted not to block traffic from port.
Did ping and telnet test and both are successful but not sure why not able to see data.
kindly let me know suggestions to fix the issue.

Regards,
MC

Tags (1)
0 Karma

munisankar
New Member

There are no errors but still am not seeing data in indexer.

In indexer am running this query - sorucetype=cisco:ise:log

I think this is correct query for searching in indexer.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...