Getting Data In

How to forward data from a syslog collection server to a third party server?

R_B
Path Finder

Hey everyone,

I currently have several devices forwarding syslog data to a syslog server. All of the devices data gets written to a directory called /syslog on the syslog server (there is a separate directory for each device inside of the /syslog directory). The syslog server uses the Universal Forwarder to forward the data in the /syslog directory to my indexers. In addition, I would like to forward all of the data being forwarded/written to the /syslog directory on the syslog server to a third party collection server. What would be the best way to forward only the data being forwarded to the /syslog directory?

Thanks in advance for any help!

0 Karma
1 Solution

starcher
Influencer

Modify your syslog configuration to also forward syslog events to your other non Splunk system.. That isn't really a Splunk forwarder issue.

View solution in original post

starcher
Influencer

Modify your syslog configuration to also forward syslog events to your other non Splunk system.. That isn't really a Splunk forwarder issue.

R_B
Path Finder

Ah sorry, I meant to ask how could I forward the data to the third party server in addition to the indexer by using the universal forwarder. In other words, how could I configure the universal forwarder to forward the data to the other server? Or really, what would be the best way to do it in this scenario?

0 Karma

starcher
Influencer

Yeah don't do that. Make your syslog server send data out as well as write to file. Not the UF. I don't think the UF even can do that. It takes an indexer and you can cause all sorts of pipeline queue blocking trying it.

R_B
Path Finder

Ok i see, that makes sense. Thank you for your feedback!

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...