Quantcast
Channel: Questions in topic: "heavy-forwarder"
Viewing all articles
Browse latest Browse all 727

How do I configure a heavy forwarder to send data to an indexer, but also send data as a single line to a syslog server?

$
0
0
Hi, I need to change a bit of my Splunk architecture and split the data output as follows: 1. Forward from Heavy Forwarder to Splunk Indexer 2. Forward from the same Heavy Forwarder to a Syslog server. The first one is easy to do, but the problem is with the second one. My server receives events which are on multiple lines (e.g. Windows Event Logs) and I need to forward them to a syslog server as single line events as a cheaper backup. How do I get the logs to forward "blindly" to one Splunk server while parsing them into one line and forwarding them to another non-splunk server? Thanks! Ken

Viewing all articles
Browse latest Browse all 727

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>