<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using UF as windows syslog forwarder in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-UF-as-windows-syslog-forwarder/m-p/606205#M13382</link>
    <description>&lt;P&gt;It seems that rsyslog's imhttp module is not that easy to get - it's not distributed with binary packages and I definitely have no time to rebuild whole packages (and look for civetweb that the module relies on and compiling that).&lt;/P&gt;&lt;P&gt;So it seems the UF-&amp;gt;rsyslog option is not really viable for me.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jul 2022 15:59:28 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2022-07-19T15:59:28Z</dc:date>
    <item>
      <title>Using UF as windows syslog forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-UF-as-windows-syslog-forwarder/m-p/605757#M13341</link>
      <description>&lt;P&gt;It's a bit off-topic but I have a kinda unusual use case. I want to get the events out of windows box and store it on a linux machine (in this particular case it's windows VM and I want to export the events to the hypervisor).&lt;/P&gt;&lt;P&gt;Of course for linux it's easiest to receive syslog messages but as we all know, Windows doesn't have built-in syslog server and you can't easily get the events with built-in windows tools to push through syslog channel.&lt;/P&gt;&lt;P&gt;So far I've been using the free SolarWinds Event Log Forwarder but it has its flaws - most notably it has problems with starting automatically with the Windows machine. It ends up with the process started but it's not forwarding events unless I manually disable and re-enable the subscriptions. That's unacceptable.&lt;/P&gt;&lt;P&gt;So I was thinking that maybe I should just install UF and instead of using splunk-tcp output just push events with plain tcp output to a syslog server. Anyone has experience with it?&lt;/P&gt;&lt;P&gt;The upside to this is that I know that UF works relatively reliably and I wouldn't have to worry about it too much.&lt;/P&gt;&lt;P&gt;The downside is that I would have to define a separate input for each event log channel (but I think I'd simply script it and have it run every few days to synchronise eventlog channels with inputs.conf).&lt;/P&gt;&lt;P&gt;I could of course set up whole Splunk Free environment on my hypervisor but it would be a huuuuuge overkill.&lt;/P&gt;&lt;P&gt;Any hints for the UF installation/configuration?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 09:43:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-UF-as-windows-syslog-forwarder/m-p/605757#M13341</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-07-15T09:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: Using UF as windows syslog forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-UF-as-windows-syslog-forwarder/m-p/605760#M13344</link>
      <description>&lt;P&gt;Bah.&lt;/P&gt;&lt;P&gt;Forgot that syslog output is not available on UF.&lt;/P&gt;&lt;P&gt;But I might try with http output and imhttp rsyslog module.&lt;/P&gt;&lt;P&gt;I'll test it some time next week probably.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 09:55:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-UF-as-windows-syslog-forwarder/m-p/605760#M13344</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-07-15T09:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: Using UF as windows syslog forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-UF-as-windows-syslog-forwarder/m-p/605773#M13350</link>
      <description>&lt;P&gt;A few years back I was using nxlog to send Windows Event Log data to external log collecting systems. It can send logs to syslog and I remember it as being rather reliable.&lt;/P&gt;&lt;P&gt;&lt;A href="https://nxlog.co/eventlog-to-syslog" target="_blank"&gt;Converting and Forwarding Windows Event Log via Syslog for Log Collection (nxlog.co)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 12:07:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-UF-as-windows-syslog-forwarder/m-p/605773#M13350</guid>
      <dc:creator>JacekF</dc:creator>
      <dc:date>2022-07-15T12:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: Using UF as windows syslog forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-UF-as-windows-syslog-forwarder/m-p/605780#M13352</link>
      <description>&lt;P&gt;Thanks for the hint. I will probably check it out. But since I had my idea, I think I will check the UF setup as well &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 12:29:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-UF-as-windows-syslog-forwarder/m-p/605780#M13352</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-07-15T12:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: Using UF as windows syslog forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Using-UF-as-windows-syslog-forwarder/m-p/606205#M13382</link>
      <description>&lt;P&gt;It seems that rsyslog's imhttp module is not that easy to get - it's not distributed with binary packages and I definitely have no time to rebuild whole packages (and look for civetweb that the module relies on and compiling that).&lt;/P&gt;&lt;P&gt;So it seems the UF-&amp;gt;rsyslog option is not really viable for me.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 15:59:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Using-UF-as-windows-syslog-forwarder/m-p/606205#M13382</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-07-19T15:59:28Z</dc:date>
    </item>
  </channel>
</rss>

