Getting Data In

_TCPRouting and _Syslog Routing to 3rd Party using a Heavy Forwarder

lukessi
Path Finder

Hello,

I need to send source types to my indexes as per normal. But I also got to send those same source types to a 3rd party in Syslog format.

I can't seem to get the transforms to send to TCP and to Syslog. Has anyone got any experience with doing this?

I can do both as TCP which works fine, but if I mix and match it has issues.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...