I'm trying to send logs from my personal router to AWS instance with Splunk capability . if there is a way i can do this from the cli needs help
Hi @navarone0161,
I'm fully agree with @PickleRick, it isn't a good idea to send raw logs on Internet and there are many ways to do this that depend on your architecture.
Have you other data sources that send logs to your AWS Splunk instance?
If yes, you should use an Heavy Forwarder as a concentrator to take the logs from all your syslog data source and concentrate the logs from other Universal Forwarder, then you can send all those logs to your Splunk instance on AWS.
So you can open as less as possible connections between your infrastructure and Interned, in addition in this way you're using an encrypted connection.
If instead you have syslogs form only one appliance, I continue to discourage to send raw logs on internet, and you should put a local instance of Splunk to receive logs and forward them to your Cloud Instance.
Ciao.
Giuseppe
"you should use an Heavy Forwarder as a concentrator to take the logs from all your syslog data source and concentrate the logs from other Universal Forwarder, then you can send all those logs to your Splunk instance on AWS"
Can you help me with the steps please using a new gen spectrum router
Hi @navarone0161,
I don't know this kind of router, but anyway the first thing you need is a machine that works as an Heavy Forwarder, the the steps are the following:
Ciao.
Giuseppe
,
im using 8.2.6
Thanks your awesome
Hi @navarone0161,
good for you, see next time!
Please accept one answer for the other people of Community
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉
To receive syslogs a Universal Forwarder would suffice. But we don't even know if the "personal router" the OP mentioned does syslog. We assumed it does so because most network appliances do.
Can you please provide me with steps how to do this from a new spectrum router
There are several possibilities from which most extreme and most discouraged is to send raw syslog over internet.
Depends on the source and your overall architecture.
its a one time class assignment i really need help
Hello navarone0161, Thank you for participating in the Splunk Community.
It could help our volunteer users to guide you if you provided more details on your assignment and where you are getting stuck.