I have an HF listener receiving syslog data from multiple sources.
The source(s) events are going to the same index causing confusion.
So I plan to create another index, separate the events, and route to the appropriate index.
I believe this can be done with inputs and transforms, but I am not finding the correct documentation.
Please advise.
Thank you
I know this might not be the answer you are looking for but if I were you I would install a dedicated Syslog server instead of using Splunk directly.
Take a look at all the following answers/posts:
https://answers.splunk.com/answers/550151/best-practices-to-send-multiple-devices-to-a-singl.html
https://www.splunk.com/blog/2016/03/11/using-syslog-ng-with-splunk.html
http://www.georgestarcher.com/splunk-success-with-syslog
https://www.function1.com/2012/05/syslog-collection-with-splunk
If you still want to go ahead with your approach (not recommended), then take a look at:
http://docs.splunk.com/Documentation/Splunk/7.0.2/Forwarding/Routeandfilterdatad
Thanks,
J
I know this might not be the answer you are looking for but if I were you I would install a dedicated Syslog server instead of using Splunk directly.
Take a look at all the following answers/posts:
https://answers.splunk.com/answers/550151/best-practices-to-send-multiple-devices-to-a-singl.html
https://www.splunk.com/blog/2016/03/11/using-syslog-ng-with-splunk.html
http://www.georgestarcher.com/splunk-success-with-syslog
https://www.function1.com/2012/05/syslog-collection-with-splunk
If you still want to go ahead with your approach (not recommended), then take a look at:
http://docs.splunk.com/Documentation/Splunk/7.0.2/Forwarding/Routeandfilterdatad
Thanks,
J
Thank you for the reply.
At this point still trying to figure out what can and cannot be done. I will definitely consider what you are suggesting. After reading your links I do remember suggesting the syslog-ng and UF option on a different deployment but in this case it would be a future option. Any suggestions to improve the "not recommended" approach would be greatly appreciated.
Thank you.