Getting Data In

How do I forward to a vm and forward it out again?

wuming79
Path Finder

Hi,

how does one forward something like sysmon from 1 vm (guest1) to another vm (guest2) and then out to another pc (outside network)?

Do I install universal forwarder and sysmon on Guest 1, and use deployment server to send out to another PC outside network?

0 Karma

wuming79
Path Finder

Is a vmware host-only guest able to forward out data to host??

0 Karma

wuming79
Path Finder

I made a mistake installing sysmon on both my guest machines and forwarding sysmon log from guest 1 (Host-only) to guest2 (Host-only and natNetwork) and intermediately forward out to another host. I thought I was looking at the sysmon log from guest 1 but realized I'm not.

How should I set up the input.conf and output.conf on guest2??

0 Karma

adonio
Ultra Champion

not sure how Deployment Server comes to play here.
Deployment Server controls the forwarders (and other splunk instances if desired) configurations
i think the only thing you need is to verify there is a connection between all 3 machines guest1, guest2, and PC.
have a forwarder collect sysmon and forward it to guest2, have guest2 listen to TCP inputs and forward out using TCP to PC.
have the PC listen to traffic from guest2 on the desired port and you are all set
hope i understand the question and i am not missing something here.

0 Karma

wuming79
Path Finder

Hi, thanks adonio, I realized I only need to setup forwarder twice on both guest machines. No need for deployment server.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...