Deployment Architecture

Intermediate Forwarder Question

stockwel
Engager

We would like to deploy intermediate forwarders in our environment. The IFs receive Windows Event logs from Universal Forwarders and the IFs send data to Splunk indexer. Currently this is working fine with Indexing turned off. The clarification i am seeking is we also would like the IF to also send the Windows event log data received from the UFs to an third party rsyslog server over UDP 514. Is this possible? If so, does the IF need to be a heavy forwarder to accomplish this? Or, can a Universal Forwarder be used for the Intermediate Forwarder? Also does the data need to be cloned at the IF in order for the Windows Event logs to be forwarded to both the Indexer and to the third party rsyslog server?

Tags (1)
0 Karma

somesoni2
Revered Legend

Yes, IF can send all data OR subset of data to a third party receiver as well, including syslog. This link should give you all the remaining answers. (section 1 - Important)

http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad

0 Karma

stockwel
Engager

Thank you! After reading the link, I am still not clear on the outputing UDP 514 part . If I receive at the IF a TCP steam, can I send out\forward to rsyslog over UDP 514? In summary, can I receive on TCP and send out\forward on UDP 514?
Or, do I also have to receive on UDP as well and change my inputs.conf to receive on udp 514? My current

Inputs.conf on the IF is :
[splunktcp://9997]
disabled = 0
compressed = false

Also, is the only way to forward on UDP 514 is using by using syslog stanza?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...