Hi
We are trying to do something which on the face of it seems fairly simple but
will not work.We have a cisco switch which is producing syslogs, normally we
use zoneranger to send them to Splunk and the records are shown.However we want
to do a bit of content routing, so we are using NiFi 0.7.3 with a ListenUDP on
port 514 and we can see the records coming in to NiFi. Without doing anything
to the records we use a putUDP to send records to the Splunk server, NiFi says
they have sent successfully but they never show in Splunk.We have used a
listenUDP on another NiFi and the records transfer and look exactly the same as
they were sent.We have also used listenSyslog and putSyslog, but the
listenSyslog says the records are invalid.
Has anyone ever to do this, and can you give us any guidance on what we may be
missing?
Many thanksDave