Alerting

How to Forward Splunk Alerts to external syslog server?

chidex123
New Member

I have a unique requirement to forward Splunk alerts to external syslog server. I have only seen use cases of forwarding data from Splunk heavy forwarder to syslog which is straightforward. However our use case is such that Splunk should forward alerts to syslog server anytime alert is triggered.  I used some syslog Mod alert from splunkbase but none worked. Any suggestions

Labels (1)
0 Karma

chidex123
New Member

Hi inventsekar,

 

Syslog is not web based and so am not sure webhook applies here as syslog uses UDP 514 as in our case

0 Karma

inventsekar
Super Champion

Hi @chidex123 ... i am not much sure,. but, pls check these:

Send alert notifications to third-party services using Splunk Observability Cloud

https://docs.splunk.com/Observability/admin/notif-services/admin-notifs-index.html

 

Send alert notifications to a webhook using Splunk Observability Cloud

https://docs.splunk.com/Observability/admin/notif-services/webhook.html

 

0 Karma

thiru_wf
Observer

@chidex123 Did you solve this issue?

0 Karma
Get Updates on the Splunk Community!

The Great Resilience Quest: 5th Leaderboard Update

The fifth leaderboard update for The Great Resilience Quest is out >> 🏆 Check out the ...

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...

There's No Place Like Chrome and the Splunk Platform

WATCH NOW!Malware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...