Deployment Architecture

How to configure Splunk forwarder for Layer7 logs?

boney_s
Explorer

Hello friends,

      I have Layer7(CA technologies) running on a virtual machine and I access it using SSH. My splunk indexer is running on another machine which is in the same network. How can I configure/install Splunk forwarder in Layer7 machine. I searched google and got documents for splunk 4.2, but it is not working for splunk 6.1 server. Please help me guys. Thanks in advance.
Tags (1)
0 Karma

Surender
Explorer

Hi Boney,

Assuming that your objective is to index layer7 logs into Splunk, best option will be to utilize syslog. Layer7 auditing and log monitoring console (GUI) allows you to send the logs to a syslog server and i am sure you can do that via command line as well.

So, build a syslog server (syslog-ng or rsyslog) that can be a standalone server with a Splunk forwarder talking to the indexer or you can install the syslog server on indexer itself and then monitor the log directory to ingest data into Splunk.

Please keep in mind when you enable logging on layer 7 by default it logs into raw format that may not be very helpful to analyze but it allows you to change the log format to standard log format as well which is easier to read than raw.

0 Karma
Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...