Getting Data In

How to send logs to multiple Windows 2008 R2 servers?

khalilrg4
New Member

I am EXTREMELY new to Splunk and I need to send my logs to multiple log servers without bringing my Splunk to the ground. ---- How can I do this?

Here the case.
- Using Splunk for my logging
- Need to have the logs that are feeding to Splunk also feed to a SIEM
- Tried this once already and Splunk basically dies

0 Karma

juvetm
Communicator

hi khaling4
You can use Attach task to this log or simply create a new scheduled task.
Use the trigger When a specific event is logged
Choose the log you want to monitor (you can choose multiple logs in the advanced task settings)
Set the action to Send an e-mail (and provide the nescessary information)
If you want any error sending a message you have to refine the trigger. Edit the trigger and choose custom. Then you have to press the button new event filter...

Tick Error in the error level part
In the drop down menu by log you can choose the log you want to monitor
With this event filter you get a message for each error that occurs.

0 Karma

khalilrg4
New Member

Got it, but this is not for a specific event. It's essentially to allow for a secondary - non-Splunk logger to get the information being sent to Splunk from Splunk.

As you can tell I am completely new to this.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...