Getting Data In

How can I configure rsyslog to send data to Splunk Entreprise ?

wafae
New Member
 
Tags (1)
0 Karma

bgaignon
Path Finder

Hi,
You have to edit the config file of your rsyslog: /etc/rsyslog.conf

I guess you already have a basic configuration.
the less you can do is:

if ($fromhost-ip == 'IP.TO.FORWARD') then @IP.SPLUNK:1514

Do not use the port 514 of course.
Now you should receive your logs on your Splunk port UDP 1514.
You have the possibility to use TCP as well.

Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...