Dashboards & Visualizations

Has anyone used syslog-ng PE as a winevent collection server?

Log_wrangler
Builder

Has anyone else used syslog-ng PE as a winevent collection server?

In my scenario, I need to send winevents to Splunk and another application (as raw data). Unfortunately sending winevents via universal forwarders > heavy forwarders (HF) > indexers (cooked) and ... HF > 3rd party app (uncooked) is dropping events.

I am posting a previous comment in this question as a reference.

Thank you

Tags (2)
0 Karma

Log_wrangler
Builder

Author :gergely_bodnar

You have mentioned syslogNG for "windows" which is part of the syslog-ng commercial offering (syslog-ng PE)
With syslog-ng PE there are two options for collecting windows logs,
- the Agent for Windows can gather locally then forward to remote syslog-ng server
- syslog-ng PE is capable to collect Windows events remotely utilising the Windows Event Collector framework.
With both solution you can feed splunk directly with syslog-ng without need any UF on the syslog side. You can use the HTTP destination to feed Splunk. Even more a dedicated Splunk destination will arrive in syslog-ng in this year supporting log batching and load balancing.

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...