Getting Data In

Capture Forwarded syslog events from a syslog server

ngcgoon
Explorer

I have setup a forwarder on a syslog-ng server to an indexer which is my webhead. I have setup an index (host-syslog) and my data input is /var/log/messages tied to that index and either the default app or unix.(The platform is linux). I have also setup a light forwarder on another syslog-ng server forwarding the events to my indexer. Somehow I can't search the webhead for events from a fowarder unless I am missing something. So on the indexer I use: host="syslog-server-host1" source ="/var/log/messages" and sourcetype = syslog. When this runs I do not get any current events and I get very few events at that. I have over 10 million lines of syslog-ng entries before the log rotates on average. Any suggestions on setup or searching?

In is there a way to make forwarded events goto a specific index on the index server? I'm using the current version 4.1.3 for linux.

Thanks any help is appreciated.

Tags (2)
0 Karma

kristian_kolb
Ultra Champion

Are you sure that you are actually searching in your dedicated syslog-index? You didn't specifically mention it.

index=host-syslog sourcetype=syslog host=syslog-server-host1 etc etc.

BR,

Kristian

0 Karma

Genti
Splunk Employee
Splunk Employee

it should be easy to achieve by the following (or similar input stanza)
[monitor:///var/log/messages/]
sourcetype = syslog
index = chosen-one

It would be beneficial to show us what the current configuration is so that we can take a peak and if needed, edit the necessary bits.

Cheers!

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...