Forward logs to Splunk or syslog
SZ-MCP can forward what happens on your network to Splunk (HTTP Event Collector) or to a syslog receiver, within a minute. It forwards alert changes, the controller’s alarms and admin activity, and changes made through SZ-MCP. It starts from the moment you add the forwarder: nothing earlier is sent. Set it up under Configure › Integrations (admins only). The rules every integration follows apply here too.
What can be forwarded?
Section titled “What can be forwarded?”Tick what to forward under Forward. Everything except controller events is ticked by default:
| Forward option | source | Default | Comes from |
|---|---|---|---|
| Alert changes (HARD states, acknowledgements, downtime) | alert | On | The alert engine. Flapping is included and SOFT states are left out |
| Controller alarms | alarm | On | The controller’s alarms, read by API polling |
| Controller events (busy: every client join and roam) | event | Off | The controller’s event log |
| Admin activity on the controller (changes and log-ons) | audit | On | The controller’s admin audit log, copied with each metric poll |
| Changes made through sz-mcp | write | On | SZ-MCP’s own write log |
Alarms and admin activity are copied from the controller by API polling, which must be on (see Metrics). Controller events are stored only from Northbound streaming, which is not available on the hosted service yet, so the event source sends nothing there.
Every record carries a stable id, so your SIEM can deduplicate.
How do I set up Splunk?
Section titled “How do I set up Splunk?”- In Splunk, create an HTTP Event Collector token, and note the collector URL.
- In SZ-MCP, open Configure › Integrations, click Add an integration, and choose Splunk (HEC).
- Enter a Name, the HEC URL (for example
https://http-inputs-acme.splunkcloud.com) and the HEC token. SZ-MCP adds/services/collector/eventif the URL doesn’t name it. - Optionally set an Index and the Splunk host field, then click Save.
- Click Send now. It sends a test record named
sz-mcp testalong with anything waiting.
Events arrive with source sz-mcp and sourcetype szmcp:<source>, for
example szmcp:alarm. Each event holds id, source, severity, name,
signature and message, plus entity, entity_name and extra fields where
they apply. Index defaults to the token’s own. The index must exist:
Splunk drops events for an unknown index without an error. Splunk host
field defaults to the controller’s host. Events go in batches of 200 with a
fixed X-Splunk-Request-Channel per integration, so tokens with indexer
acknowledgement work.
How do I set up syslog?
Section titled “How do I set up syslog?”- In SZ-MCP, open Configure › Integrations, click Add an integration, and choose Syslog (CEF or JSON).
- Enter a Name, the Syslog server and the Port. Leave Port empty for 6514 with TLS or 514 without.
- Choose the format, framing, TLS and facility (below), then click Save.
- Click Send now to send a test record.
| Field | Default | Choices |
|---|---|---|
| Format | CEF | CEF or JSON |
| Framing | Octet counting (RFC 5425) | Octet counting, or One message per line |
| TLS (turn off only on a private path) | On | TLS needs a publicly trusted certificate on the receiver |
| Facility (16 = local0) | 16 | 0–23 |
| HOSTNAME | The controller’s host | Any printable text without spaces |
Messages are RFC 5424 syslog over TCP, with app name sz-mcp and the source
(alert, alarm …) as the message id. In CEF the vendor is sz-mcp, the
product SmartZone and the version the controller’s. JSON carries the same
fields as the Splunk event.
How does delivery work?
Section titled “How does delivery work?”- Every minute, each forwarder sends what happened since its last successful send.
- At least once. The position moves only after a successful send, so a
failed minute is retried the next minute. Duplicates are possible after a
failure. Deduplicate on
id. - Up to 5,000 rows a minute of each kind. A run reads up to 5 pages of 1,000 rows each from three places: the controller’s log (alarms, events and admin activity together), the alert changes, and SZ-MCP’s writes. A backlog catches up over the following minutes, and the result says “more to send next minute”.
- Editing keeps the position, so changing a setting doesn’t re-send or skip anything. A source you tick later starts at the present.
- Recent deliveries (as
splunk_hec:<name>orsyslog:<name>) logs failures, the first success after a failure, and Send now. It does not log every minute’s batch.
What errors can I get?
Section titled “What errors can I get?”| Message | Cause |
|---|---|
Splunk HEC: HTTP <status> … | Splunk refused the batch. The message includes Splunk’s reason and how many were sent before it |
url: the URL must be https | The HEC URL isn’t https |
server: port 25 is not allowed | Port 25 can’t be used |