Getting Data In

How to forward txt files or data from window server using Splunk forwarder to remote server?

anilkapoor123
Explorer

Hi Team,

i want to check whether is it feasible to send data or txt files exist in a folder using splunk forwarder to remote system or syslog server 

please suggest me steps to do it

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

While it is possible on Heavy Forwarder (syslog output is not available on UF), it doesn't make much sense. There are several syslog daemons for windows.

Also, using Splunk server this way might not be exactly permitted by the license, especially if you don't use Splunk in your environment otherwise.

anilkapoor123
Explorer

@PickleRick 

query.

i am able to forward iis logs from window server using splunk forwarder to heavy forwarder [ splunk forwarder --> Heavy forwarder --> syslog remote server

but heavy forwarder not able to send logs or data to syslog server .

is there any way to check whether it is sending data or not from HF to syslog server

please share the configuration at HF end to send data to syslog server

specifically that props.conf , transforms.conf , outputs.conf 

any setting needed for inputs.conf as well at HF end ?

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Yes, there is a way to check whether your HF is sending to syslog server. Just do a tcpdump/wireshark and see if there is data flowing over the wire to your syslog destination.

What is your configuration? What have _you_ tried so far to make the forwarding to syslog work?

And why do you insist on using Splunk components for something that doesn't have much to do with Splunk at all.

0 Karma

anilkapoor123
Explorer

@PickleRick ,

you mean with heavyforwarder it is possible to fwd txt logs files exist in folder . if it is possible 

please share me the configurations file for inputs.conf and outputs.conf  whatever needed to send data to syslog server

0 Karma
Get Updates on the Splunk Community!

The Payment Operations Wake-Up Call: Why Financial Institutions Can't Afford ...

The same scenario plays out across financial institutions daily. A payment system fails at 11:30 AM on a busy ...

Make Your Case: A Ready-to-Send Letter for Getting Approval to Attend .conf25

Hello Splunkers, Want to attend .conf25 in Boston this year but not sure how to convince your manager? We've ...

Community Spotlight: A Splunk Expert's Journey

In the world of data analytics, some journeys leave a lasting impact not only on the individual but on the ...