Hello
We have 2 Data Center locations and each location has 3 indexers that collect logs from Universal Forwarders in each location. All indexers from the 2 DC locations are replicated for redundancy and Disaster Recovery purposes.
My questions:
1. Is it possible to forward all raw logs from all indexers to a 3rd party SIEM directly without a Heavy Forwarder?
2. Do I need to change props.conf and transforms.conf for each indexers or at Cluster Master?
We have Splunk 6.2.3
Thanks in advance.
Your questions:
1. Is it possible to forward all raw logs from all indexers to a 3rd party SIEM directly without a Heavy Forwarder? - Yes it is possible .Because they are forwarding to a non-Splunk system, they can send only raw data.
e.g.
outputs.conf
[syslog:webreports_syslog_group]
server = myhostname:514
type = tcp
transforms.conf
[send_to_webreports]
REGEX = .
DEST_KEY = _SYSLOG_ROUTING
FORMAT = webreports_syslog_group
props.conf:
[source::/data/logs/httpd/somesite/access*]
TRANSFORMS-weblog-matrix = send_to_webreports
Your questions:
1. Is it possible to forward all raw logs from all indexers to a 3rd party SIEM directly without a Heavy Forwarder? - Yes it is possible .Because they are forwarding to a non-Splunk system, they can send only raw data.
e.g.
outputs.conf
[syslog:webreports_syslog_group]
server = myhostname:514
type = tcp
transforms.conf
[send_to_webreports]
REGEX = .
DEST_KEY = _SYSLOG_ROUTING
FORMAT = webreports_syslog_group
props.conf:
[source::/data/logs/httpd/somesite/access*]
TRANSFORMS-weblog-matrix = send_to_webreports
I'm unable forward specific INDIEX from HF to syslog . please check the configurations which I have used
props.conf
[index::watson]
TRANSFORMS-watson = wat_to_syslog
transforms.conf
[wat_to_syslog]
REGEX = .
DEST_KEY = _SYSLOG_ROUTING
FORMAT = wat_syslog_group
outputs.conf
[syslog:wat_syslog_group]
server = splunk-syslog.XXXX.com:514
type=udp