Sending json logs with syslog-ng to Splunk via HEC

Carlos Lopez <[email protected]> Wed, 28 Sep 2022 10:08:48 +0000
Newsgroups gmane.comp.syslog-ng
Message-ID <[email protected]>
Hi all,

I am trying to configure syslog-ng to send events in json format to our internal Splunk (free version) server.

Searching info regarding how to accomplish this config, I see these entries in Balabit’s blog:

https://www.syslog-ng.com/community/b/blog/posts/optimize-your-splunk-infrastructure-using-new-syslog-ng-features 

https://www.syslog-ng.com/community/b/blog/posts/sending-logs-splunk-http

Are these entries accurate to accomplish this config? Somebody can share any sample?

I am using syslog-ng’ OSS under FreeBSD 13.1 hosts …

Best regards,
C. L. Martinez



______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.balabit.com/wiki/syslog-ng-faq