Getting Data In

Forward logs to third party and no duplicates in splunk

Anto
Explorer

I want to forward logs to third party system (syslog) without index these data into splunk but i can't accomplish it, help.

On my heavy forwarder i set up outputs.conf, transforms.conf, props.conf as follow:

 

outuputs.conf

[syslog:my_syslog_group]
server = <IP>:PORT

 

transforms.conf

[send_to_syslog]
REGEX = MY REGEX
DEST_KEY = _SYSLOG_ROUTING
FORMAT = my_syslog_group

[not_send_to_syslog]
REGEX = MY REGEX
DEST_KEY =queue
FORMAT =nullQueue

 

 

props.conf

[source::MY_SOURCE]
TRANSFORMS-t0=send_to_syslog,not_send_to_syslog


In this way logs don't forward to my syslog, they will be just deleted and not indexed. Removing [not_send_to_syslog] from props and transforms data will be indexed on splunk and also forwarded to syslog.

How can i achieve my problem, sending data to syslog and not indexing them on splunk? Thanks in advantage to those who will help me.

0 Karma
1 Solution

Anto
Explorer

I find out the solution. In the transform.conf just replace DEST_KEY as follow:

[not_send_to_syslog]
REGEX = MY REGEX
DEST_KEY =_TCP_ROUTING
FORMAT =nullQueue

 

All done now. thanks to all

 

View solution in original post

Anto
Explorer

I find out the solution. In the transform.conf just replace DEST_KEY as follow:

[not_send_to_syslog]
REGEX = MY REGEX
DEST_KEY =_TCP_ROUTING
FORMAT =nullQueue

 

All done now. thanks to all

 

scelikok
SplunkTrust
SplunkTrust

Hi @Anto,

Can you try changing the order of transforms in props.conf

[source::MY_SOURCE]
TRANSFORMS-t0=not_send_to_syslog, send_to_syslog

 

If this reply helps you an upvote is appreciated.
0 Karma

Anto
Explorer

Thank you for your answer but it didn't help. Logs aren't forwarded to syslog and they entered in nullqueue so i don't saw them also in splunk. Any other ideas?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What's the point of sending data to Splunk if it won't be indexed?  Send the syslog data directly to the syslog server.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

Anto
Explorer

Because i don't need them for the analysis in Splunk but i want to preserve the logs  without exceed my license just for 2 GB. So you are telling me that this isn't possible to do directly from splunk? Thank you for your reply, i want just to understand

0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...

Reminder! Splunk Love Promo: $25 Visa Gift Card for Your Honest SOAR Review With ...

We recently launched our first Splunk Love Special, and it's gone phenomenally well, so we're doing it again, ...