Deployment Architecture

How to configure Splunk to collect syslog and forward the raw data to a 3rd party SIEM directly from a clustered indexer?

scorpia
New Member

Hello

We have 2 Data Center locations and each location has 3 indexers that collect logs from Universal Forwarders in each location. All indexers from the 2 DC locations are replicated for redundancy and Disaster Recovery purposes.

My questions:
1. Is it possible to forward all raw logs from all indexers to a 3rd party SIEM directly without a Heavy Forwarder?
2. Do I need to change props.conf and transforms.conf for each indexers or at Cluster Master?

We have Splunk 6.2.3

Thanks in advance.

0 Karma
1 Solution

jensonthottian
Contributor

Your questions:
1. Is it possible to forward all raw logs from all indexers to a 3rd party SIEM directly without a Heavy Forwarder? - Yes it is possible .Because they are forwarding to a non-Splunk system, they can send only raw data.

e.g.
outputs.conf

[syslog:webreports_syslog_group]
server = myhostname:514
type = tcp

transforms.conf
[send_to_webreports]
REGEX = .
DEST_KEY = _SYSLOG_ROUTING
FORMAT = webreports_syslog_group

props.conf:

[source::/data/logs/httpd/somesite/access*]
TRANSFORMS-weblog-matrix = send_to_webreports

  1. Do I need to change props.conf and transforms.conf for each indexers or at Cluster Master? In each indexer for the sources you want to send.

View solution in original post

0 Karma

jensonthottian
Contributor

Your questions:
1. Is it possible to forward all raw logs from all indexers to a 3rd party SIEM directly without a Heavy Forwarder? - Yes it is possible .Because they are forwarding to a non-Splunk system, they can send only raw data.

e.g.
outputs.conf

[syslog:webreports_syslog_group]
server = myhostname:514
type = tcp

transforms.conf
[send_to_webreports]
REGEX = .
DEST_KEY = _SYSLOG_ROUTING
FORMAT = webreports_syslog_group

props.conf:

[source::/data/logs/httpd/somesite/access*]
TRANSFORMS-weblog-matrix = send_to_webreports

  1. Do I need to change props.conf and transforms.conf for each indexers or at Cluster Master? In each indexer for the sources you want to send.
0 Karma

cleelakrishna
Loves-to-Learn

I'm unable forward specific INDIEX from HF to syslog . please check the configurations which I have used
props.conf
[index::watson]
TRANSFORMS-watson = wat_to_syslog

transforms.conf
[wat_to_syslog]
REGEX = .
DEST_KEY = _SYSLOG_ROUTING
FORMAT = wat_syslog_group

outputs.conf

[syslog:wat_syslog_group]
server = splunk-syslog.XXXX.com:514
type=udp

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...