Deployment Architecture

Intermediate Forwarder Question

stockwel
Engager

We would like to deploy intermediate forwarders in our environment. The IFs receive Windows Event logs from Universal Forwarders and the IFs send data to Splunk indexer. Currently this is working fine with Indexing turned off. The clarification i am seeking is we also would like the IF to also send the Windows event log data received from the UFs to an third party rsyslog server over UDP 514. Is this possible? If so, does the IF need to be a heavy forwarder to accomplish this? Or, can a Universal Forwarder be used for the Intermediate Forwarder? Also does the data need to be cloned at the IF in order for the Windows Event logs to be forwarded to both the Indexer and to the third party rsyslog server?

Tags (1)
0 Karma

somesoni2
Revered Legend

Yes, IF can send all data OR subset of data to a third party receiver as well, including syslog. This link should give you all the remaining answers. (section 1 - Important)

http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad

0 Karma

stockwel
Engager

Thank you! After reading the link, I am still not clear on the outputing UDP 514 part . If I receive at the IF a TCP steam, can I send out\forward to rsyslog over UDP 514? In summary, can I receive on TCP and send out\forward on UDP 514?
Or, do I also have to receive on UDP as well and change my inputs.conf to receive on udp 514? My current

Inputs.conf on the IF is :
[splunktcp://9997]
disabled = 0
compressed = false

Also, is the only way to forward on UDP 514 is using by using syslog stanza?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...