Getting Data In

How to forward txt files or data from window server using Splunk forwarder to remote server?

anilkapoor123
Explorer

Hi Team,

i want to check whether is it feasible to send data or txt files exist in a folder using splunk forwarder to remote system or syslog server 

please suggest me steps to do it

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

While it is possible on Heavy Forwarder (syslog output is not available on UF), it doesn't make much sense. There are several syslog daemons for windows.

Also, using Splunk server this way might not be exactly permitted by the license, especially if you don't use Splunk in your environment otherwise.

anilkapoor123
Explorer

@PickleRick 

query.

i am able to forward iis logs from window server using splunk forwarder to heavy forwarder [ splunk forwarder --> Heavy forwarder --> syslog remote server

but heavy forwarder not able to send logs or data to syslog server .

is there any way to check whether it is sending data or not from HF to syslog server

please share the configuration at HF end to send data to syslog server

specifically that props.conf , transforms.conf , outputs.conf 

any setting needed for inputs.conf as well at HF end ?

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Yes, there is a way to check whether your HF is sending to syslog server. Just do a tcpdump/wireshark and see if there is data flowing over the wire to your syslog destination.

What is your configuration? What have _you_ tried so far to make the forwarding to syslog work?

And why do you insist on using Splunk components for something that doesn't have much to do with Splunk at all.

0 Karma

anilkapoor123
Explorer

@PickleRick ,

you mean with heavyforwarder it is possible to fwd txt logs files exist in folder . if it is possible 

please share me the configurations file for inputs.conf and outputs.conf  whatever needed to send data to syslog server

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...