Deployment Architecture

Intermediate Forwarder Question

stockwel
Engager

We would like to deploy intermediate forwarders in our environment. The IFs receive Windows Event logs from Universal Forwarders and the IFs send data to Splunk indexer. Currently this is working fine with Indexing turned off. The clarification i am seeking is we also would like the IF to also send the Windows event log data received from the UFs to an third party rsyslog server over UDP 514. Is this possible? If so, does the IF need to be a heavy forwarder to accomplish this? Or, can a Universal Forwarder be used for the Intermediate Forwarder? Also does the data need to be cloned at the IF in order for the Windows Event logs to be forwarded to both the Indexer and to the third party rsyslog server?

Tags (1)
0 Karma

somesoni2
Revered Legend

Yes, IF can send all data OR subset of data to a third party receiver as well, including syslog. This link should give you all the remaining answers. (section 1 - Important)

http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad

0 Karma

stockwel
Engager

Thank you! After reading the link, I am still not clear on the outputing UDP 514 part . If I receive at the IF a TCP steam, can I send out\forward to rsyslog over UDP 514? In summary, can I receive on TCP and send out\forward on UDP 514?
Or, do I also have to receive on UDP as well and change my inputs.conf to receive on udp 514? My current

Inputs.conf on the IF is :
[splunktcp://9997]
disabled = 0
compressed = false

Also, is the only way to forward on UDP 514 is using by using syslog stanza?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...