Getting Data In

Login to resource from Universal Forwarder?

lbogle
Contributor

Hello,
I am trying to get logs sent from a firewall to a Universal Forwarder. To get logs from the Firewall, I need to configure the Universal Forwarder to provide the firewall with login credentials. Can I do this with a Universal Forwarder or do I need to use a heavy forwarder?
Thanks.

0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi lbogle,

reading your question, first thing that came up was why not use a scripted input to get these logs?
So did you check out the docs about scripted inputs?

Basically you create a script to get the logs and run this script cron like from the universal forwarder.

hope this helps ...

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi lbogle,

reading your question, first thing that came up was why not use a scripted input to get these logs?
So did you check out the docs about scripted inputs?

Basically you create a script to get the logs and run this script cron like from the universal forwarder.

hope this helps ...

cheers, MuS

martin_mueller
SplunkTrust
SplunkTrust

Well, without any more info I don't know what to say.

0 Karma

lbogle
Contributor

Ha! I guess thats the question. The firewall need authentication credentials before it will allow the logs to leave so I'm not sure honestly...
Is there a spot in the universal forwarder to supply this information?
It may be too complex a request for the universal forwarder to do.
Thanks Martin.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

How does this kind of input work?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...