Splunk Universal Forwarder
Configuring Splunk Universal Forwarder to send data to LOGIQ
Splunk universal forwarders support forwarding raw data as it is collected as well in Splunk's proprietary protocol S2S. LOGIQ.AI can directly ingest from Splunk UF in the raw mode that does not use proprietary S2S protocol.
Splunk Universal Forwarder can be configured to send raw TCP data to LOGIQ. To enable forwarding to LOGIQ edit
$SPLUNK_HOME/etc/system/local/outputs.conf
file and enable TCP forwarding.[tcpout]
disabled = false
defaultGroup = logiq
[tcpout:logiq]
server = <logiq_instance>:<raw port>
sendCookedData=false
negotiateProtocolLevel = 0
LOGIQ.AI can ingest data from Splunk forwarders in cooked mode as well. You can create an S2S Ingest app extension to directly ingest data from Splunk universal forwarder and Heavy forwarder in cooked mode.
Logs/Events/Metrics can be ingested into LOGIQ.AI using cooked mode
Go to "Explore" -> "App Extensions" and create your S2S Ingest app extension

S2S Cooked mode plugin
Multiple S2s Ingest extensions can be running simultaneously
Last modified 2mo ago