All Apps and Add-ons

Splunk event forwarding

shaileshpawar21
New Member

Hello,
I have tried to forward log event stored in splunk to Linux machine via syslog.
but only splunk specific events (means events that are generated by splunk not the stored events) are forwarded to linux machine.
can anybody please tell me about process of forwarding stored events from splunk to other linux/windows box.?? please

thanks in advance

0 Karma

kristian_kolb
Ultra Champion

You can forward incoming events to a third party system (i.e. a non-splunk system). From the wording of your question it seems like you have set this up with partial success. I believe that you wish to forward data that has already been indexed by a splunk indexer. To the best of my knowledge that is not as straightforward as it might seem, unfortunately. Once event have been indexed (i.e. you don't forward the incoming stream of events), you'll have make searches and export the search results.

http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Forwarddatatothird-partysystemsd
http://docs.splunk.com/Documentation/Splunk/5.0.2/Knowledge/Savingsearchesandsharingsearchresults
http://splunk-base.splunk.com/answers/46050/export-raw-logs-from-specific-time

Hope this helps,

Kristian

0 Karma

shaileshpawar21
New Member

Hi Ayn,

I have followed all steps given in link but events are not forwarded to other machine.
I have done following steps.
1st received events from TCP port
then in foward made the configuration of hostname:port
the host which is mentioned has beed configured to read events through syslog. (for this edited rsyslog.conf)
but events are not present in log file of other machine..
Please help me,
Thanks.

0 Karma

Ayn
Legend

You can't grab events right from the raw index files. You need to go through the regular Splunk mechanisms, which the docs that kristian links to describe. Is there anything in particular that you're missing in the docs? Because I see instructions there on how to grab all or just a subset of the events and forward it to a 3rd party system over TCP...

0 Karma

shaileshpawar21
New Member

Thanks Kristian,
I want to forward data(events) which is stored in index(journal.gz file) to the remote on third party non splunk machine via TCP port through syslog.
How should I do that ?
Please help me in this.

Thanks in advance

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...