Splunk Search

Splunk Standalone forward data to syslog


We have a relatively small Splunk implementation - just 1 standalone server. We're downloading Cisco Umbrella logs from the Cisco-managed S3 Bucket for reporting purposes.

We now have the need to also forward those umbrella logs to a syslog server in addition to leaving them on the standalone for reporting. Is there a way to configure a standalone to forward to a syslog server?

Tags (1)
0 Karma


Hi mpuchalski,

Please read this https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd#Sysl... it can be configured on any Splunk instance. Just a word of caution: if you configure forwarding to a third party receiver and the receiving end goes down or is not available you will get in trouble on your Splunk instance.

Hope this helps ...

cheers, MuS

0 Karma


With this standalone instance, I have multiple apps receiving data.  I only want 1 index to fwd to an external syslog server.  Is that possible without a heavy forwarder?

0 Karma


Thank you. What is the trouble that Splunk will experience is the receiver is not available?

0 Karma
Get Updates on the Splunk Community!

Splunk Platform | Upgrading your Splunk Deployment to Python 3.9

Splunk initially announced the removal of Python 2 during the release of Splunk Enterprise 8.0.0, aiming to ...

From Product Design to User Insights: Boosting App Developer Identity on Splunkbase

co-authored by Yiyun Zhu & Dan Hosaka Engaging with the Community at .conf24 At .conf24, we revitalized the ...

Detect and Resolve Issues in a Kubernetes Environment

We’ve gone through common problems one can encounter in a Kubernetes environment, their impacts, and the ...