Hi all, I have hundreds of UF (universal forwarders) setup and sending wineventlogs to our splunk cloud instance. There is a requirement to also send the wineventlogs to our parent company, but they have logrhythm. I have setup a separate app under apps/logrhythm and it's successfully sending data to both splunk cloud and the logrhythm collector. The log rhythm collector sadly can't parse the data, so tried to change the it to XML via the renderXML directive via the below. C:\Program Files\SplunkUniversalForwarder\etc\apps\logrhythm\default\inputs.conf [WinEventLog://Application]
index = wineventlog
renderXml = true
disabled = 0
[WinEventLog://Security]
index = wineventlog
renderXml = true
disabled = 0
[WinEventLog://System]
index = wineventlog
renderXml = true
disabled = 0 C:\Program Files\SplunkUniversalForwarder\etc\apps\logrhythm\default\inputs.conf [tcpout]
defaultGroup = logrhythm,splunkcloud
[tcpout:logrhythm]
server = <Servername>:514
sendCookedData = falsecompressed = false
dnsResolutionInterval = 60 Sadly, this also sends XML format windows event logs to our splunk instance in the cloud - this completely mangles it and doesn't match all our other data sent with wineventlog What is the best way to send wineventlog data, as set previously, to splunk cloud and XML wineventlog data to logrhythm??
... View more