<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk audit log in syslog output in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-audit-log-in-syslog-output/m-p/13880#M1298</link>
    <description>&lt;P&gt;I have my splunk instance set up to receive data on a TCP port, sourcetype it, then output it with to a Splunk receiver using the forwarder/receiver configuration.  Everything is okay with that, my problem comes in when I try to configure a syslog output, as talked about &lt;A href="http://www.splunk.com/base/Documentation/4.1.2/Admin/Forwarddatatothird-partysystems" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.2/Admin/Forwarddatatothird-partysystems&lt;/A&gt; and &lt;A href="http://www.splunk.com/base/Documentation/4.0/Admin/ForwardtosyslogorHTTP" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.0/Admin/ForwardtosyslogorHTTP&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The remote server receives the data as I intended, but it also receives a whole bunch of Splunk audit events, particularly whenever a user uses the web interface.&lt;/P&gt;

&lt;P&gt;outputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[syslog]
defaultGroup=logserver

[syslog:logserver]
server = logserver:12345
type = tcp
sendCookedData = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[to-be-syslogged]
TRANSFORMS-syslog = send_to_syslog
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[send_to_syslog]
REGEX = .*
DEST_KEY = _SYSLOG_ROUTING
FORMAT = logserver
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It is my understanding that the bracket inside of props.conf specifies the sourcetype that I would like output to syslog.  I have also tried host::* (and various iterations of server names), and source::tcp:5557 (the port that these particular entries are coming in on) to no avail.&lt;/P&gt;

&lt;P&gt;The logs I am seeing on my syslog server include the logs I am looking for, but also have multiple entries such as:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;13&amp;gt;Audit:[timestamp=05-19-2010 14:52:32.090, user=admin, action=admin_all_objects, info=granted ][n/a]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 20 May 2010 01:54:41 GMT</pubDate>
    <dc:creator>adamw</dc:creator>
    <dc:date>2010-05-20T01:54:41Z</dc:date>
    <item>
      <title>Splunk audit log in syslog output</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-audit-log-in-syslog-output/m-p/13880#M1298</link>
      <description>&lt;P&gt;I have my splunk instance set up to receive data on a TCP port, sourcetype it, then output it with to a Splunk receiver using the forwarder/receiver configuration.  Everything is okay with that, my problem comes in when I try to configure a syslog output, as talked about &lt;A href="http://www.splunk.com/base/Documentation/4.1.2/Admin/Forwarddatatothird-partysystems" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.2/Admin/Forwarddatatothird-partysystems&lt;/A&gt; and &lt;A href="http://www.splunk.com/base/Documentation/4.0/Admin/ForwardtosyslogorHTTP" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.0/Admin/ForwardtosyslogorHTTP&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The remote server receives the data as I intended, but it also receives a whole bunch of Splunk audit events, particularly whenever a user uses the web interface.&lt;/P&gt;

&lt;P&gt;outputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[syslog]
defaultGroup=logserver

[syslog:logserver]
server = logserver:12345
type = tcp
sendCookedData = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[to-be-syslogged]
TRANSFORMS-syslog = send_to_syslog
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[send_to_syslog]
REGEX = .*
DEST_KEY = _SYSLOG_ROUTING
FORMAT = logserver
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It is my understanding that the bracket inside of props.conf specifies the sourcetype that I would like output to syslog.  I have also tried host::* (and various iterations of server names), and source::tcp:5557 (the port that these particular entries are coming in on) to no avail.&lt;/P&gt;

&lt;P&gt;The logs I am seeing on my syslog server include the logs I am looking for, but also have multiple entries such as:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;13&amp;gt;Audit:[timestamp=05-19-2010 14:52:32.090, user=admin, action=admin_all_objects, info=granted ][n/a]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2010 01:54:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-audit-log-in-syslog-output/m-p/13880#M1298</guid>
      <dc:creator>adamw</dc:creator>
      <dc:date>2010-05-20T01:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk audit log in syslog output</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-audit-log-in-syslog-output/m-p/13881#M1299</link>
      <description>&lt;P&gt;Had the same problem. If you are using a regular forwarder (not a lightweight), you need to configure the indexer to receive the data using splunktcp instead of tcp.  You can either user the default splunktcp port 9997, or add a new one. To add a new splunktcp to the indexer, navigate to: Manager &amp;gt;&amp;gt; Forwarding and Receiving &amp;gt;&amp;gt; Receive Data &amp;gt;&amp;gt; add new.  Specify the port number. You will need to configure the forwarder to set sourcetype.  &lt;/P&gt;

&lt;P&gt;From the input.conf documentation &lt;/P&gt;

&lt;P&gt;&lt;B&gt;[splunktcp://:]&lt;BR /&gt;
* This is the same as TCP, except the remote server is assumed to be a Splunk server. &lt;/B&gt;&lt;/P&gt;

&lt;P&gt;Worked for me!&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2010 20:42:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-audit-log-in-syslog-output/m-p/13881#M1299</guid>
      <dc:creator>carmackd</dc:creator>
      <dc:date>2010-07-06T20:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk audit log in syslog output</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-audit-log-in-syslog-output/m-p/13882#M1300</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Correction:&lt;/STRONG&gt;  Events coming from either normal splunk forwarders &lt;EM&gt;or&lt;/EM&gt; lightweight splunk forwarders should &lt;STRONG&gt;both&lt;/STRONG&gt; be received using the &lt;CODE&gt;splunktcp&lt;/CODE&gt; input.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2010 23:18:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-audit-log-in-syslog-output/m-p/13882#M1300</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-07-06T23:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk audit log in syslog output</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-audit-log-in-syslog-output/m-p/13883#M1301</link>
      <description>&lt;P&gt;Am I reading this correctly in that you are doing Server -&amp;gt; Syslog -&amp;gt; Splunk Forwarder -&amp;gt; Syslog -&amp;gt; Splunk Indexer?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2010 00:28:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-audit-log-in-syslog-output/m-p/13883#M1301</guid>
      <dc:creator>ftk</dc:creator>
      <dc:date>2010-07-21T00:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk audit log in syslog output</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-audit-log-in-syslog-output/m-p/13884#M1302</link>
      <description>&lt;P&gt;definitely not, just raw TCP stream -&amp;gt; splunk -&amp;gt; syslog&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2010 23:06:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-audit-log-in-syslog-output/m-p/13884#M1302</guid>
      <dc:creator>adamw</dc:creator>
      <dc:date>2010-07-28T23:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk audit log in syslog output</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-audit-log-in-syslog-output/m-p/13885#M1303</link>
      <description>&lt;P&gt;Have you tried removing:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[syslog]&lt;/CODE&gt;&lt;BR /&gt;
&lt;CODE&gt;defaultGroup=logserver&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;from your outputs.conf?&lt;/P&gt;

&lt;P&gt;As I read it and from my own experience it might change the behaviour from what you intend. Otherwise it looks good. If all else fails you can use REGEX = to negate certain log entries.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2010 20:26:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-audit-log-in-syslog-output/m-p/13885#M1303</guid>
      <dc:creator>stephanbuys</dc:creator>
      <dc:date>2010-08-24T20:26:59Z</dc:date>
    </item>
  </channel>
</rss>

