Dashboards & Visualizations

Has anyone used syslog-ng PE as a winevent collection server?

Log_wrangler
Builder

Has anyone else used syslog-ng PE as a winevent collection server?

In my scenario, I need to send winevents to Splunk and another application (as raw data). Unfortunately sending winevents via universal forwarders > heavy forwarders (HF) > indexers (cooked) and ... HF > 3rd party app (uncooked) is dropping events.

I am posting a previous comment in this question as a reference.

Thank you

Tags (2)
0 Karma

Log_wrangler
Builder

Author :gergely_bodnar

You have mentioned syslogNG for "windows" which is part of the syslog-ng commercial offering (syslog-ng PE)
With syslog-ng PE there are two options for collecting windows logs,
- the Agent for Windows can gather locally then forward to remote syslog-ng server
- syslog-ng PE is capable to collect Windows events remotely utilising the Windows Event Collector framework.
With both solution you can feed splunk directly with syslog-ng without need any UF on the syslog side. You can use the HTTP destination to feed Splunk. Even more a dedicated Splunk destination will arrive in syslog-ng in this year supporting log batching and load balancing.

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...