Hello there, I'm newbie to splunk and need your help please to forward syslog logs coming to splunk to another third party linux server. I can clearly see on my SH instance, that there are logs with sourcetype=syslog. but when I use a heavy forwarder to forward these logs I receive nothing. I configured teh receiving of heavy forwarder to listen to 9997. then my sources would send their logs to the HV using 9997. The HF also transmit all he receives to Splunk SH on 9997 and i'm also trying to transmit syslog to third party server. when I configure the outputs with the following configuration for syslog . I receive nothing on my server.
[syslog]
defaultGroup=syslogGroup
[syslog:syslogGroup]
and when I just use
[tcpout:custom_group]
server = ip:port
sendCookedData = false
I receive all kind of data and none is tagged with sourcetype. although i can see among them syslog event, but they are not tagged properly.
Please help me out. Thanks in advance
... View more