Monitor network ports using Splunk Light

You can monitor TCP or UDP ports to add data from the syslog service on one or more machines.

Select the network source

1. In the Add Data view, click Monitor.

2. Select TCP/UDP to view the configuration options for network ports.

3. Select either TCP or UDP.

4. Type in the Port number.

For example, the standard port for TCP is 9997 and for UDP is 514.

5. (Optional) Next to Source name override, type in a custom source name using the format host:port.

6. (Optional) Next to Only accept connection from, type in the name, IP address, or fully qualified domain name for each host. You can use wildcards to specify more than one host. This setting restricts the data input to specific machines or devices.

7. Click Next to continue.

Specify input settings

Use the Input Settings to modify the source type, host, and index assignments for the incoming network data.

1. Select the Source type from the list of predefined source types or type it in manually.

2. (Optional) Assign the Host field value.

  • Select IP for IP addresses.
  • Select DNS for domain name system.
  • Select Custom to type in a host name.

3. (Optional) Select a different Index to store the data.

You can Create a new index and refresh the list of indexes. By default all data saves to the default main index.

4. Click Review to continue.

Review and Save

1. Review the summary of your data input.

2. (Optional) Go back to make changes.

3. Click Submit to complete the add data process.

Last modified on 05 April, 2016
