They are transmitted via the UDP port to our Splunk syslog server. On the Clearpass application, UDP port 4514 has been entered. When you type the tcpudump command (tcpdump -i eth0 port 4514), you can see that it receives the frames on the syslog. Yes we have an UF on the Syslog server. However, I have the impression that it does not send them to the indexer. How can I correct this?
... View more