Getting Data In

Splunk Forwarder/syslog-ng filter

miguel1423
Explorer

Hello,

I use cp_log_export on my checkpoint management server to send logs (CEF format) to my syslog-ng server and on the same server, my splunk forwarder send log to my splunk server.

I got too many logs from checkpoint and I would like to know if I can did some filters on splunk forwarder or syslog-ng server before ? 

for the moment in my syslog-ng I filter uniquely with tho IP source of my checkpoint management server and in my splunk forwarder with the sourcetype (checkpoint:cef).

splunk_forwarder.png

 

 

After regarding the logs on splunk, I would like to get only the logs from the cef_product MTA, can I filter that on splunk forwarder or syslog-ng ? I prefer filtered syslog-ng to reduce the amount of logs in my syslog server.

cef_mta.png

 

 

Regards,

 

 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...