Getting Data In

How do I configure a heavy forwarder to send data to an indexer, but also send data as a single line to a syslog server?

kengilmour
Path Finder

Hi,

I need to change a bit of my Splunk architecture and split the data output as follows:

  1. Forward from Heavy Forwarder to Splunk Indexer
  2. Forward from the same Heavy Forwarder to a Syslog server.

The first one is easy to do, but the problem is with the second one. My server receives events which are on multiple lines (e.g. Windows Event Logs) and I need to forward them to a syslog server as single line events as a cheaper backup.

How do I get the logs to forward "blindly" to one Splunk server while parsing them into one line and forwarding them to another non-splunk server?

Thanks!

Ken

0 Karma

CletisSWRX
New Member

There is a way to do this. There is a way that the original message can be copied, transform applied, and sent out to the syslog server. This way the original log in WEF format is indexed in its original state and the syslog server receives tab delim single line format. I've seen it in use, I just don't have the code.

0 Karma

kengilmour
Path Finder

Thanks @CletisSWRX , but this was almost 4 years ago - I no longer use Splunk - I use CyberEasy now.

0 Karma

javiergn
Super Champion

I think your approach is only going to work with Syslog events and the extra effort of having to sylog-ize your remaining ones is probably going to be huge.

Some thoughts:

  • Use a product such as Snare in order to get those event logs via Syslog
  • Backup your raw data straight from your indexer
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...