# How to send logs to Splunk server

**URL:** <https://forums.suse.com/t/how-to-send-logs-to-splunk-server/30224>\
**Category:** SLES Configure-Administer\
**Created:** [August 24, 2017, 2:12pm UTC](https://forums.suse.com/t/how-to-send-logs-to-splunk-server/30224 "2017-08-24T14:12:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dvbell](https://avatars.discourse-cdn.com/v4/letter/d/d6d6ee/32.png) [@dvbell](https://forums.suse.com/u/dvbell)\
**Post date:** [August 24, 2017, 2:12pm UTC](https://forums.suse.com/t/how-to-send-logs-to-splunk-server/30224/1 "2017-08-24T14:12:35Z")

</div>

I used /etc/syslog-ng/syslog-ng.conf in SLES11 to send logs to our Splunk server, but SLES12 does not use syslog-ng. How do I send logs to Splunk in SLES12?

---

<div class="post-metadata">

**Author:** ![ab1](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@ab1](https://forums.suse.com/u/ab1)\
**Post date:** [August 24, 2017, 3:02pm UTC](https://forums.suse.com/t/how-to-send-logs-to-splunk-server/30224/2 "2017-08-24T15:02:17Z")

</div>

I believe rsyslog is used in SLES 12, so Google provides hits there, but  
essentially add a line like the following to, preferably, a new file under  
/etc/rsyslog.d/ named for what you want to do:

```auto
*.* @@192.168.1.1:10514
```

–  
Good luck.

If you find this post helpful and are logged into the web interface,  
show your appreciation and click on the star below.

If you want to send me a private message, please let me know in the  
forum as I do not use the web interface often.

---

<div class="post-metadata">

**Author:** ![smflood](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/smflood/32/10576_2.png) [@smflood](https://forums.suse.com/u/smflood)\
**Post date:** [August 24, 2017, 3:26pm UTC](https://forums.suse.com/t/how-to-send-logs-to-splunk-server/30224/3 "2017-08-24T15:26:13Z")

</div>

On 24/08/17 13:02, ab wrote:  
[color=blue]

> I believe rsyslog is used in SLES 12, so Google provides hits there, but  
> essentially add a line like the following to, preferably, a new file under  
> /etc/rsyslog.d/ named for what you want to do:
> 
> `
> *.* @@192.168.1.1:10514
> `[/color]

Both /etc/rsyslog.conf (and /etc/rsyslog.d/remote.conf referenced by  
rsyslog.conf) note the need to enable on-disk queues in remote.conf when  
using remote logging so you should do that too!

## HTH.

Simon  
SUSE Knowledge Partner

* * *

## If you find this post helpful and are logged into the web interface, please show your appreciation and click on the star below. Thanks.
