I had a similar issue. I have syslog coming into splunk via UDP 514.
I was not getting any data into the Sonicwall Analytics App.
I found that the external collector was not configured.
Once I made sure Splunk was listening on port 2055, I then proceeded to setup the External Collector to use Splunk. All the data was visible via the Sonicwall Analytics app Dashboard(s) after the External Collector was setup.
... View more