Deployment Architecture

How to forward filtered events from Splunk to another Splunk receiver

gblondeau
New Member

Hi everyone,

I'm looking for a solution to forward some events to another Splunk Server. I need to forward specific events only (eg. events with httpCode=500). I saw in the documentation that I can deploy a universal forwarder and then configure filters by editing props.conf. From what I understood, forwarders are set up on each server where we need to capture data. I would like to avoid this and have a centralized solution.

I'm wondering if it's the only way to do it. Is it possible to set a search in Splunk web UI and then send the events to a particular server?

My concern is to be able to filter events from a centralized server.

Thanks for your help

Tags (1)
0 Karma
1 Solution

MuS
Legend

Hi gblondeau,

you can setup a deployment server which will be the centralized configuration server for the universal forwarders. Nevertheless, filtering will be done in your case on an indexer, because this is data parsing which will not be done by the universal forwarder. So you must setup props.conf and transforms.conf according the docs on your indexer.

hope this helps to get you started ...

cheers, MuS

View solution in original post

MuS
Legend

Hi gblondeau,

you can setup a deployment server which will be the centralized configuration server for the universal forwarders. Nevertheless, filtering will be done in your case on an indexer, because this is data parsing which will not be done by the universal forwarder. So you must setup props.conf and transforms.conf according the docs on your indexer.

hope this helps to get you started ...

cheers, MuS

MuS
Legend

Regarding the configuration: basically you could also use any other tool that is able to change files on a server, like Puppet.
Regarding the filtering: no, this is how it is done 🙂

0 Karma

gblondeau
New Member

Hey Mus,

Thanks for your answer. I'll take a look at the deployment server + universal forwarder.

Otherwise, is there any other solution?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...