rsyslog.conf停止接收日志:打印机日志无法传入Splunk的技术求助
Let's work through this step by step to get your printer logs flowing into Splunk—relay projects can have weird leftover configs, so we'll narrow down the issue methodically:
1. First, confirm rsyslog is actually receiving printer logs
If rsyslog isn't getting the logs from your printer, forwarding to Splunk is impossible. Here's how to check:
- Capture incoming traffic: Run
sudo tcpdump -i any udp port [打印机发送的端口](replace with the port you set on the printer to send logs to your Linux server). Then trigger a test print—you should see packets coming from the printer's IP. - Check local syslogs: Look in
/var/log/syslogor/var/log/messagesfor entries tagged with your printer's name/IP. If you see them here, rsyslog is receiving logs; if not, double-check the printer's log destination settings (IP/port) and ensure your Linux server's firewall allows that port.
2. Verify rsyslog's forwarding config to Splunk
The previous student's rsyslog.conf might have missing or incorrect rules to send logs to Splunk's 2048 port. Update it with these steps:
- Open
/etc/rsyslog.conf(or/etc/rsyslog.d/99-splunk.confif they used a separate config file) and add a rule to forward printer logs:# Forward printer-specific logs to Splunk on TCP port 2048 :programname, contains, "printer" @@localhost:2048 # OR, if filtering by printer IP: :fromhost-ip, isequal, "[打印机IP]" @@localhost:2048- Use
@@for TCP (most common for Splunk) or@for UDP—match the protocol you set in Splunk's listener.
- Use
- Restart rsyslog to apply changes:
sudo systemctl restart rsyslog
3. Test connectivity between rsyslog and Splunk
Even if the config looks right, network issues can block logs:
- Check port reachability: Run
nc -zv [Splunk服务器IP] 2048(uselocalhostif Splunk is on the same Linux server). If it says "Connection refused", check Splunk's firewall rules or confirm the listener is actually running. - Check rsyslog errors: Look in
/var/log/rsyslog.logfor lines like "action 'action-1' suspended"—these indicate rsyslog can't reach Splunk.
4. Validate Splunk's listener setup
Make sure Splunk is actually listening for logs on 2048:
- Check your Splunk input config (usually in
$SPLUNK_HOME/etc/apps/search/local/inputs.conf)—it should have something like:[tcp://2048] disabled = false sourcetype = printer_logs # Optional but helpful for filtering - Search Splunk for test logs: Manually send a test message with
echo "Test printer log entry" | nc [Splunk IP] 2048, then searchindex=* "Test printer log entry"in Splunk. If you find it, Splunk is working; if not, recheck the listener settings.
5. Rule out edge cases
- Outdated hardcoded values: The previous config might have hardcoded IPs (like an old Splunk server IP) that don't match your current setup—grep the config for IPs with
grep -E "[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+" /etc/rsyslog.confto check. - SELinux/AppArmor: If your Linux server uses SELinux, it might block rsyslog from sending traffic to Splunk. Temporarily set it to permissive with
sudo setenforce 0to test (don't forget to re-enable later if that fixes it).
Since this is a multi-year relay project, it's super common for configs to drift from the actual setup. Taking it one step at a time should help you find where the log flow is breaking.
内容的提问来源于stack exchange,提问作者depressedGirl

