Hello All:
Greetings. First of all, thanks for take your time and read this question; apologies by my poor English.
I'm really N00b about Splunk Enterprise and Splunk Forwarder, but I must be involved in a project in my work, so I must be learn!!!. I deeply read this article (https://answers.splunk.com/answers/333248/how-to-implement-tagging-on-a-universal-forwarder.html), this (https://answers.splunk.com/answers/129225/tag-data-on-universal-forwarder.html) and this (https://answers.splunk.com/answers/501121/how-to-add-custom-tags-to-event-data-via-universal.html) related to my question, but I don't understand very well those answers.
This is my scenario: In premise, a server is installed with a number of virtual machines (VMs), one of them have Splunk Forwarder installed. Other VMs have applications generating logs we want to analyze. In other site, we have another server running Splunk Enterprise.
We want to collect information from VMs and send to Splunk Enterprise via Splunk Forwarder for futher analysis, but we want to tag this information to categorize it and do analysis. For example, if VM1 run App1 and generating LogApp1, we want to send this data to Splunk Enterprise and be able to do several search, analysis, filters over LogApp1 data.
So:
What is the right configuration over log data in VMs and Splunk Forwarder to tagging, categorize it in order to identifying in Splunk Enterprise? I'm thinking in use syslog to send data from VMs o Splunk Forwarder, but How I must tag this data in order to get a tagged data and not a mess?
Can you provide me full example in how I must configure VM, syslog (if this is part of solution), Splunk Forwarder and Splunk Enterprise (Is indexers involved here?)
Please, I really N00b about Splunk Architecture and any help will be appreciated, even if you consider basic your support, guide, advice or answer. I really open to Splunk 101 answers.
Please, let me note if you need further explanation about my problem, I hope I had described enough.
Thank you very much and best regards,
Rafael
... View more