Dear Experts,
We have a Distributed environment using around 5 heavy forwarders across various locations sending logs to a central indexer. Now we have a requirement to forward the raw logs to another log management/SIEM solution.
What do you guys recommend to forward the logs? We are looking for a way to centrally forwarding the logs,
Thanks in advance !
Hi,
Forwarding from every HF will be the easy way to do it.
http://docs.splunk.com/Documentation/Splunk/6.4.1/Forwarding/Forwarddatatothird-partysystemsd
Hope i help you