Splunk Enterprise

Forwarding splunk to 3rd party collector

michaelking
Engager

Hi folks,

I am seeking some assistance with the formatting of forwarded splunk data to a 3rd party collector, we have managed to get everything forwarding fine by configuring C:\Program Files\Splunk\etc\system\local\outputs.conf

[syslog]

defaultGroup=syslogGroup

maxEventSize = 65535

[syslog:syslogGroup]

server = IPAddress:514

type = tcp

 

The problem is that all (windows logs only) we get every field of a log as a separate event that multiplies traffic drastically. I read briefly about line breaking but not sure how to configure this and we only have a live environment and wouldn’t want to make any changes that could potentially break our existing Splunk instance as it’s used heavily by all our I.T departments.

 

Any advice would be appreciated.

 

Cheers!

Labels (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @michaelking,

I think the issue is on the receiver side since we are using this setup to forward windows security events to Cyberark PTA without a problem. You should check options on Exabeam receiver. 

I also recommend using UDP syslog output, because if the receiver side does not listen or receive events fast enough your Splunk indexing process may blocked. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

michaelking
Engager

Thanks@scelikok

 

I will get the exabeam people to take another look, they indicated it was an issue with the splunk side as they done the same setup with some of our other sites.

 

I tried UDP initially but it would only work for 10minutes then start erroring, when I switched to TCP it seemed more stable.

 

Cheers

0 Karma

michaelking
Engager

Sorry I forgot to mention, the collector is a Linux based system using an installation of Exabeam to collect the data.

 

Cheers

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...