Getting Data In

using splunk heavyforwarder to forward to syslog only not forwarding to index

dwart
New Member

log sources coming in from UniversalForwarderto Heavyforwarder looking to selectively forward to syslog without indexing on the heavyforwarder or index cluster, these selective logs need to only forward to syslog central logging system only

syslog output is working already on the heavyforwarder and indexing on the heavyforwarder is disabled, but events are being indexed on the index host/cluster, is there a configuration/deployment where HeavyForwarder selectively only forwarded to syslog without any indexing ?

 

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

here is instructions how to forward data to external syslog server: https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd#Sysl...

You just need to add selection which events you want to send to syslog and which to splunk. Also that is described in above document.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...