Getting Data In

Export to Syslog

Scarecrowddb
Explorer

Hi All,

Does anyone know if it's possible to take logs that have been grabbed from Windows WMI and indexed, and then forward them on to a syslog server?

This is a requirement here that needs to be met before the Admins will consider the program... needless to say it's causing me some grief so I thought I'd put it out here and see if any guru's can point me in the right direction...

Cheers,

DB

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Sure. You can have Splunk forward on anything it indexes via syslog format. Generally, you configure the indexers to forward on syslog, not the forwarders. The thing to note is that Splunk's Windows Event Logs will have internal newline characters. It shouldn't cause any problems with receiving syslog agents, depending what they do with it though. I would nevertheless have you test it against your preferred receiver to see if you like the results.

http://www.splunk.com/base/Documentation/latest/Admin/Forwarddatatothird-partysystems#Forward_syslog...

View solution in original post

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Sure. You can have Splunk forward on anything it indexes via syslog format. Generally, you configure the indexers to forward on syslog, not the forwarders. The thing to note is that Splunk's Windows Event Logs will have internal newline characters. It shouldn't cause any problems with receiving syslog agents, depending what they do with it though. I would nevertheless have you test it against your preferred receiver to see if you like the results.

http://www.splunk.com/base/Documentation/latest/Admin/Forwarddatatothird-partysystems#Forward_syslog...

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...