I need to send windows event logs from Splunkforwarder to Indexers via a heavyforwarder.
I have done some configuration but it seems like something is incorrect as I am getting cooked data in splunk instead of logs.
All the help is appreciated.
Splunk forwarder: outputs.conf
Heavy forwarder : inputs.conf
disabled = 0
inputs on indexers :
Okay got it, I have changed it to splunktcp on forwarder and even I can read the logs in splunk SH but still sourcetype of logs is coming in as xmlWinEventlog instead of WinEventLog. I have the SpluK_TA_Windows on indexers as well as on HF and SF. But this I think is close to resolving the issue if i can just sort this small thing.
so you mean to say in splunkforwarder inputs.conf i should set renderXML = false and that should fix it or will i have to do that everywhere like on SF,HF,IX all 3 places? sorry doing this for the first time. Getting windows logs is easiest of all but the way i am trying its looking very difficult.
thanks in advance.
OK. Baby steps 🙂
In the inputs.conf file on the UF you set how you want the events from the EventLog pulled - as XML or not.
Then you send it to HF, which sends data to indexer(s).
The app installed on the SH-s are responsible for search-time extractions.
I don't remember if the TA for windows does any index-time data modifications - you have to check the docs. If it does, you'd also need it on the HF. But I don't recall installing it there.