Getting Data In

How Do You Forward Data to Syslog Server and Indexers?

Path Finder

What I am trying to do is to get a particular source type forwarded from the heavy forwarder to a syslog server. In addition, I want the data to also go to my indexers. Is it possible to do this? What configuration would be needed?

0 Karma
1 Solution

Splunk Employee
Splunk Employee

check this link:

http://docs.splunk.com/Documentation/Splunk/7.1.2/Forwarding/Forwarddatatothird-partysystemsd#Forwar...

mention the source type and configure props.conf & transforms.conf followed by outputs.conf

Also, check the below Splunk accepted answer

https://answers.splunk.com/answers/211403/how-to-configure-inputsconf-and-outputsconf-on-the.html

View solution in original post

0 Karma

Splunk Employee
Splunk Employee

Hi @rajindurbal - Did one of the answers below help provide a solution to your question? If yes, please click “Accept” below the best answer to resolve this post and upvote anything that was helpful. If no, please leave a comment with more feedback. Thanks for posting!

0 Karma

Motivator

Hey rajindurbal,

To forward data from heavy forwarder to syslog server .
Refer : http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd

To forward data to indexers as well:
https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Forwardsearchheaddata

Splunk Employee
Splunk Employee

check this link:

http://docs.splunk.com/Documentation/Splunk/7.1.2/Forwarding/Forwarddatatothird-partysystemsd#Forwar...

mention the source type and configure props.conf & transforms.conf followed by outputs.conf

Also, check the below Splunk accepted answer

https://answers.splunk.com/answers/211403/how-to-configure-inputsconf-and-outputsconf-on-the.html

View solution in original post

0 Karma