I am trying to configure Splunk as a syslog server, I created a syslog app and I tried configure it to capture packets on UDP port 514 using the input.conf file, but it didnt work.
I read about a way to make Kiwi syslog capture the syslog msgs and make Splunk monitor the log file. I tried it but still.
I doubt that the app is missconfigured coz it does not retrieve any input from the file. I think whats missing is to instruct the syslog app to graph and analyze the inputs, but how can that be done?
your help is greatly appreciated,