Getting Data In

Export to Syslog

Scarecrowddb
Explorer

Hi All,

Does anyone know if it's possible to take logs that have been grabbed from Windows WMI and indexed, and then forward them on to a syslog server?

This is a requirement here that needs to be met before the Admins will consider the program... needless to say it's causing me some grief so I thought I'd put it out here and see if any guru's can point me in the right direction...

Cheers,

DB

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Sure. You can have Splunk forward on anything it indexes via syslog format. Generally, you configure the indexers to forward on syslog, not the forwarders. The thing to note is that Splunk's Windows Event Logs will have internal newline characters. It shouldn't cause any problems with receiving syslog agents, depending what they do with it though. I would nevertheless have you test it against your preferred receiver to see if you like the results.

http://www.splunk.com/base/Documentation/latest/Admin/Forwarddatatothird-partysystems#Forward_syslog...

View solution in original post

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Sure. You can have Splunk forward on anything it indexes via syslog format. Generally, you configure the indexers to forward on syslog, not the forwarders. The thing to note is that Splunk's Windows Event Logs will have internal newline characters. It shouldn't cause any problems with receiving syslog agents, depending what they do with it though. I would nevertheless have you test it against your preferred receiver to see if you like the results.

http://www.splunk.com/base/Documentation/latest/Admin/Forwarddatatothird-partysystems#Forward_syslog...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...