Getting Data In

Hiow to forward events from servers and network devices

ppram
New Member

We have a splunk Indexer based on Linux and we have around 40+ servers and network devices in our network.

Want to know how to get all these servers and network devices forward SYSlogs and event logs to the splunk Indexer.

Do I have to install a splunk agent in all the servers? If Yes, what is a Splunk Agent? How do I tell the network devices to send the SYSlog and SNMP logs to Splunk Indexer?

0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hello ppram

best thing to do, read the manual http://www.splunk.com/base/Documentation/latest/Data/WhatSplunkcanmonitor and I think all your questions will be answered.

regards, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hello ppram

best thing to do, read the manual http://www.splunk.com/base/Documentation/latest/Data/WhatSplunkcanmonitor and I think all your questions will be answered.

regards, MuS

MuS
SplunkTrust
SplunkTrust

Hi ppram

yes, install a light weight forwarder or as from 4.2 on, an universal forwarder on that windows server, configure it as needed and your done.

ppram
New Member

HI MuS,

Thanks for helping me on this. Now for example if I have a windows server I want to collect all the windows event logs and send it to the Splunk Indexer in another server.

I need to install the splunk in that Windows server and then install the windows APP and forward the log to the Splunk Indexer server?

Please correct me if I am wrong.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...