We would like to deploy intermediate forwarders in our environment. The IFs receive Windows Event logs from Universal Forwarders and the IFs send data to Splunk indexer. Currently this is working fine with Indexing turned off. The clarification i am seeking is we also would like the IF to also send the Windows event log data received from the UFs to an third party rsyslog server over UDP 514. Is this possible? If so, does the IF need to be a heavy forwarder to accomplish this? Or, can a Universal Forwarder be used for the Intermediate Forwarder? Also does the data need to be cloned at the IF in order for the Windows Event logs to be forwarded to both the Indexer and to the third party rsyslog server?
Yes, IF can send all data OR subset of data to a third party receiver as well, including syslog. This link should give you all the remaining answers. (section 1 - Important)
http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad
Thank you! After reading the link, I am still not clear on the outputing UDP 514 part . If I receive at the IF a TCP steam, can I send out\forward to rsyslog over UDP 514? In summary, can I receive on TCP and send out\forward on UDP 514?
Or, do I also have to receive on UDP as well and change my inputs.conf to receive on udp 514? My current
Inputs.conf on the IF is :
[splunktcp://9997]
disabled = 0
compressed = false
Also, is the only way to forward on UDP 514 is using by using syslog stanza?