Skip to content
SZ-MCP
Get Support

Forward logs to Splunk or syslog

SZ-MCP can forward what happens on your network to Splunk (HTTP Event Collector) or to a syslog receiver, within a minute. It forwards alert changes, the controller’s alarms and admin activity, and changes made through SZ-MCP. It starts from the moment you add the forwarder: nothing earlier is sent. Set it up under Configure › Integrations (admins only). The rules every integration follows apply here too.

Tick what to forward under Forward. Everything except controller events is ticked by default:

Forward optionsourceDefaultComes from
Alert changes (HARD states, acknowledgements, downtime)alertOnThe alert engine. Flapping is included and SOFT states are left out
Controller alarmsalarmOnThe controller’s alarms, read by API polling
Controller events (busy: every client join and roam)eventOffThe controller’s event log
Admin activity on the controller (changes and log-ons)auditOnThe controller’s admin audit log, copied with each metric poll
Changes made through sz-mcpwriteOnSZ-MCP’s own write log

Alarms and admin activity are copied from the controller by API polling, which must be on (see Metrics). Controller events are stored only from Northbound streaming, which is not available on the hosted service yet, so the event source sends nothing there.

Every record carries a stable id, so your SIEM can deduplicate.

  1. In Splunk, create an HTTP Event Collector token, and note the collector URL.
  2. In SZ-MCP, open Configure › Integrations, click Add an integration, and choose Splunk (HEC).
  3. Enter a Name, the HEC URL (for example https://http-inputs-acme.splunkcloud.com) and the HEC token. SZ-MCP adds /services/collector/event if the URL doesn’t name it.
  4. Optionally set an Index and the Splunk host field, then click Save.
  5. Click Send now. It sends a test record named sz-mcp test along with anything waiting.

Events arrive with source sz-mcp and sourcetype szmcp:<source>, for example szmcp:alarm. Each event holds id, source, severity, name, signature and message, plus entity, entity_name and extra fields where they apply. Index defaults to the token’s own. The index must exist: Splunk drops events for an unknown index without an error. Splunk host field defaults to the controller’s host. Events go in batches of 200 with a fixed X-Splunk-Request-Channel per integration, so tokens with indexer acknowledgement work.

  1. In SZ-MCP, open Configure › Integrations, click Add an integration, and choose Syslog (CEF or JSON).
  2. Enter a Name, the Syslog server and the Port. Leave Port empty for 6514 with TLS or 514 without.
  3. Choose the format, framing, TLS and facility (below), then click Save.
  4. Click Send now to send a test record.
FieldDefaultChoices
FormatCEFCEF or JSON
FramingOctet counting (RFC 5425)Octet counting, or One message per line
TLS (turn off only on a private path)OnTLS needs a publicly trusted certificate on the receiver
Facility (16 = local0)160–23
HOSTNAMEThe controller’s hostAny printable text without spaces

Messages are RFC 5424 syslog over TCP, with app name sz-mcp and the source (alert, alarm …) as the message id. In CEF the vendor is sz-mcp, the product SmartZone and the version the controller’s. JSON carries the same fields as the Splunk event.

  • Every minute, each forwarder sends what happened since its last successful send.
  • At least once. The position moves only after a successful send, so a failed minute is retried the next minute. Duplicates are possible after a failure. Deduplicate on id.
  • Up to 5,000 rows a minute of each kind. A run reads up to 5 pages of 1,000 rows each from three places: the controller’s log (alarms, events and admin activity together), the alert changes, and SZ-MCP’s writes. A backlog catches up over the following minutes, and the result says “more to send next minute”.
  • Editing keeps the position, so changing a setting doesn’t re-send or skip anything. A source you tick later starts at the present.
  • Recent deliveries (as splunk_hec:<name> or syslog:<name>) logs failures, the first success after a failure, and Send now. It does not log every minute’s batch.
MessageCause
Splunk HEC: HTTP <status> …Splunk refused the batch. The message includes Splunk’s reason and how many were sent before it
url: the URL must be httpsThe HEC URL isn’t https
server: port 25 is not allowedPort 25 can’t be used