Getting Data In

Routing and filtering syslog

ezparra05
Engager

Have Palo Alto logs being sent to syslog-ng server. A UF is on the syslog-ng and forwarding logs to Heavy Forwarder. I have a list of specific firewall (hostnames) and zones that I need to filter a copy of the traffic by and send to different (separate)  indexer . Is it possible to filter and route using either the UF or HF?

Labels (2)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @ezparra05,

You should use HF for route/filter data. Please see below document.

https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Get Updates on the Splunk Community!

Transforming Financial Data into Fraud Intelligence

Every day, banks and financial companies handle millions of transactions, logins, and customer interactions ...

How to send events & findings from AWS to Splunk using Amazon EventBridge

Amazon EventBridge is a serverless service that uses events to connect application components together, making ...

Exciting News: The AppDynamics Community Joins Splunk!

Hello Splunkers,   I’d like to introduce myself—I’m Ryan, the former AppDynamics Community Manager, and I’m ...