Getting Data In

How can I configure rsyslog to send data to Splunk Entreprise ?

wafae
New Member
 
Tags (1)
0 Karma

bgaignon
Path Finder

Hi,
You have to edit the config file of your rsyslog: /etc/rsyslog.conf

I guess you already have a basic configuration.
the less you can do is:

if ($fromhost-ip == 'IP.TO.FORWARD') then @IP.SPLUNK:1514

Do not use the port 514 of course.
Now you should receive your logs on your Splunk port UDP 1514.
You have the possibility to use TCP as well.

Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...