We would like to deploy intermediate forwarders in our environment. The IFs receive Windows Event logs from Universal Forwarders and the IFs send data to Splunk indexer. Currently this is working fine with Indexing turned off. The clarification i am seeking is we also would like the IF to also send the Windows event log data received from the UFs to an third party rsyslog server over UDP 514. Is this possible? If so, does the IF need to be a heavy forwarder to accomplish this? Or, can a Universal Forwarder be used for the Intermediate Forwarder? Also does the data need to be cloned at the IF in order for the Windows Event logs to be forwarded to both the Indexer and to the third party rsyslog server?
↧