Getting Data In

Export to Syslog

Scarecrowddb
Explorer

Hi All,

Does anyone know if it's possible to take logs that have been grabbed from Windows WMI and indexed, and then forward them on to a syslog server?

This is a requirement here that needs to be met before the Admins will consider the program... needless to say it's causing me some grief so I thought I'd put it out here and see if any guru's can point me in the right direction...

Cheers,

DB

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Sure. You can have Splunk forward on anything it indexes via syslog format. Generally, you configure the indexers to forward on syslog, not the forwarders. The thing to note is that Splunk's Windows Event Logs will have internal newline characters. It shouldn't cause any problems with receiving syslog agents, depending what they do with it though. I would nevertheless have you test it against your preferred receiver to see if you like the results.

http://www.splunk.com/base/Documentation/latest/Admin/Forwarddatatothird-partysystems#Forward_syslog...

View solution in original post

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Sure. You can have Splunk forward on anything it indexes via syslog format. Generally, you configure the indexers to forward on syslog, not the forwarders. The thing to note is that Splunk's Windows Event Logs will have internal newline characters. It shouldn't cause any problems with receiving syslog agents, depending what they do with it though. I would nevertheless have you test it against your preferred receiver to see if you like the results.

http://www.splunk.com/base/Documentation/latest/Admin/Forwarddatatothird-partysystems#Forward_syslog...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...