Getting Data In

Forward logs to third party and no duplicates in splunk

Anto
Explorer

I want to forward logs to third party system (syslog) without index these data into splunk but i can't accomplish it, help.

On my heavy forwarder i set up outputs.conf, transforms.conf, props.conf as follow:

 

outuputs.conf

[syslog:my_syslog_group]
server = <IP>:PORT

 

transforms.conf

[send_to_syslog]
REGEX = MY REGEX
DEST_KEY = _SYSLOG_ROUTING
FORMAT = my_syslog_group

[not_send_to_syslog]
REGEX = MY REGEX
DEST_KEY =queue
FORMAT =nullQueue

 

 

props.conf

[source::MY_SOURCE]
TRANSFORMS-t0=send_to_syslog,not_send_to_syslog


In this way logs don't forward to my syslog, they will be just deleted and not indexed. Removing [not_send_to_syslog] from props and transforms data will be indexed on splunk and also forwarded to syslog.

How can i achieve my problem, sending data to syslog and not indexing them on splunk? Thanks in advantage to those who will help me.

0 Karma
1 Solution

Anto
Explorer

I find out the solution. In the transform.conf just replace DEST_KEY as follow:

[not_send_to_syslog]
REGEX = MY REGEX
DEST_KEY =_TCP_ROUTING
FORMAT =nullQueue

 

All done now. thanks to all

 

View solution in original post

Anto
Explorer

I find out the solution. In the transform.conf just replace DEST_KEY as follow:

[not_send_to_syslog]
REGEX = MY REGEX
DEST_KEY =_TCP_ROUTING
FORMAT =nullQueue

 

All done now. thanks to all

 

View solution in original post

scelikok
Champion

Hi @Anto,

Can you try changing the order of transforms in props.conf

[source::MY_SOURCE]
TRANSFORMS-t0=not_send_to_syslog, send_to_syslog

 

If this reply helps you an upvote is appreciated.
0 Karma

Anto
Explorer

Thank you for your answer but it didn't help. Logs aren't forwarded to syslog and they entered in nullqueue so i don't saw them also in splunk. Any other ideas?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

What's the point of sending data to Splunk if it won't be indexed?  Send the syslog data directly to the syslog server.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

Anto
Explorer

Because i don't need them for the analysis in Splunk but i want to preserve the logs  without exceed my license just for 2 GB. So you are telling me that this isn't possible to do directly from splunk? Thank you for your reply, i want just to understand

0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!