Hi,
from splunk, how can i check what are the logs is being forwarded out to another SIEM?
output.conf is configured to forward syslog, what does the syslog containing?
Hi @SamYap ,
you have to see in one props.conf and transforms.conf what you are forwarding.
You can recognize the tranformation because it will contain the option:
DEST_KEY = _SYSLOG_ROUTING
as you can see at https://docs.splunk.com/Documentation/Splunk/7.2.3/Forwarding/Forwarddatatothird-partysystemsd?_gl=1...
Ciao.
Giuseppe