Can anyone confirm if a log file that has been created as part of a processing rule can be used as an import source for a Splunk Instance, and is anyone currently doing this?
We currently use the free Solarwinds Event Log forwarder to send all of our AD event logs to our Kiwi Syslog Server, from there we processes these messages and amongst other things output these messages to a log file that we wish to use an an import source.
Splunk seem to imply that these log files cannot be used as an input source using their native Splunk add-on for Microsoft Windows, however i believe that Solarwinds imply that these can be used for import to a Splunk instance.
So who is right and who is wrong, and how can it be done if it can be done, have i potentially missed a step?