Yes, Nagios Log Server can filter and send important events to Splunk. I have done this with load-balanced outputs to Splunk forwarders using the
syslog output rule.
As mentioned in my first post:
mcapra wrote:It sort of depends on some specifics of your Splunk architecture.
We still don't know anything about your Splunk setup, so we can't tell you the best way to configure Nagios Log Server to your liking.
hyacinth wrote:Is there any scheme can work on that ?
As mentioned in my first post, the most common solution is to configure a
syslog output rule in Nagios Log Server which is pointed at a Splunk forwarder:
Assuming your architecture includes one or several Splunk forwarders, I would suggest first getting that
syslog output rule correctly configured in Nagios Log Server. Then once Splunk is receiving messages, you can worry about the filtering.
If you have trouble configuring the
syslog output, that is definitely something we can assist with if you provide us with the error messages you receive. We simply cannot tell you exactly where to point the
syslog output unless we know some basic stuff about your Splunk setup, though.