2012-01-30
11:25 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
How to receive log, forwarded by SPLUNK?
I am able to forward log from SPLUNK to another syslog server. From envision side, I don't know how to receive it. I started to look at Manage file reader service under Universal device collection under system configuration. I am looking at similar message service like APACHE file reader service. I am not sure I should add SPLUNK into file reader service or LEA client Service or SDEE collection service. I would really appreciate your help. Thanks
1 Reply
2012-02-24
03:36 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
It depends on how you can send/get it from splunk. Syslog, file or ODBC?
Once you figure out your method, then you need to get a copy of the log data into envision, using the method chosen.
Then you have to use Event Source Integrator to build out your cutom XML for your logs from splunk, which likely do not match what came from the original device (if that is the intent).
ESI can work well. We've used it ourselves to validate/design our custom efforts. But it is not a trivial effort, it takes a bit to figure out. Read the documentation for it.
