Getting Data In

Can you configure a heavy forwarder to route raw data to a local file?

Log_wrangler
Builder

I need a capture some raw data before it is indexed and sent to a 3rd party application (via tcp_routing and transforms-routing)

I would like to send it to a local dir/file... is that possible?

Please advise...

Thank you

Tags (3)
0 Karma
1 Solution

FrankVl
Ultra Champion

Not that I’m aware of, at least not directly. What you could do as a workaround I guess is run a syslog daemon on that system as an intermediate. Send it to local host using syslog routing and then have the syslog daemon write it to file.

View solution in original post

0 Karma

FrankVl
Ultra Champion

Not that I’m aware of, at least not directly. What you could do as a workaround I guess is run a syslog daemon on that system as an intermediate. Send it to local host using syslog routing and then have the syslog daemon write it to file.

0 Karma

Log_wrangler
Builder

that's an option thanks

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...