Getting Data In

Splunk HF send only auditd, syslog, linux_secure to 3rd party syslog

ZimmermanC1
Explorer

I am having trouble wrapping my head around how to configure a HF to forward the sourcetypes of syslog and auditd to a 3rd party syslog host as well as to an indexer, without sending other sourcetypes as well.

I am trying to use a combination of these to docs to help but I have not been successful yet.
Route and filter data
Forward data to third-party systems

My configs look like this right now.

props.conf

[syslog]
TRANSFORMS-routing = routeAll, send_to_syslog

[auditd]
TRANSFORMS-routing = routeAll, send_to_syslog

[cpu]
TRANSFORMS-routing = routeAll

[ps]
TRANSFORMS-routing = routeAll

transforms.conf

[routeAll]
REGEX = (.)
DEST_KEY = _TCP_ROUTING
FORMAT = default-autolb-group

[send_to_syslog]
REGEX = (.)
DEST_KEY = _SYSLOG_ROUTING
FORMAT = syslogGroup

outputs.conf

[tcpout]
defaultGroup = default-autolb-group

[tcpout:default-autolb-group]
server = Y.Y.Y.Y:9997

[tcpout-server://Y.Y.Y.Y:9997]

[indexAndForward]
index = false

[syslog]
defaultGroup=syslogGroup

[syslog:syslogGroup]
server = X.X.X.X:514
sendCookedData = false
type = tcp
0 Karma

abhijeet01
Path Finder

Hi ZimmermanC1 ,

PFB link for forwarding syslog log data to indexer or third part syslog host by HF.

https://splunkonbigdata.com/2019/07/09/syslog-integration-with-splunk/

Let me know.

0 Karma

ZimmermanC1
Explorer

My issue is that i need a configuration that will only forward events to my 3rd party syslog server that come from monitoring of:
/var/log/messages
/var/log/secure
/var/log/audit/audit.log
Even if I have other scripts running via the Splunk_TA_nix app on each UF that is feeding the HF.

Right now I can only get the HF to send all events to both the Splunk Indexers and the 3rd party syslog server.
As an example, I have ps.sh enabled to run every 10 minutes via Splunk_TA_nix on each machine that has a UF installed on it. I want the PS events to go to the indexers but not into the 3rd party syslog server.

0 Karma

ZimmermanC1
Explorer

No, there is only 1 HF collecting from dozens of UF. The HF is being used as a network segmentation conduit.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ZimmermanC1,
what's the wrong behaviour you have?
Have you also other Heavy Forwarders that sends these logs to this HF?

Ciao.
Giuseppe

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ZimmermanC1,
OK what's the wrong behaviour you have?

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...