How to configure splunk with Bigfix & syslog connector

Are you asking how to install the Splunk Forwarders with IEM/Bigfix?
Or are you asking how to connect Splunk to Bigfix?

I’m also curious about using Splunk to gather and report on BigFix infrastructure logs.

I have never used it, and I’m not certain what it does, but there is this:

Also an analysis for reporting on Splunk Config:

Thanks for your replies, i have running splunk application in the current environment , just want to know how bigfix application redirect its logs to splunk via syslog connector?

We use Splunk for all manner of things, but I haven’t thought of having it harvest from BigFix. What are the things y’all would solve by this?

how to configure BigFix syslog connector for splunk

So after tangling with that app for a few months I can tell you a couple things about it (at least from the perspective of our environment).

  1. It was built and configured to work with BigFix version 7.0 and support is spotty at best for it.
  2. If your BigFix server is not ready to handle the requests from the Python scripts that collect the data from web reports using the SOAP API, it can cause other reporting from the Web Reports to be very late because it’s dealing with the requests from Splunk.
  3. The current Python scripts that were shipped with the app (at least in my environment) treated all the information it received from BigFix as an error and thus did not index it at all even though it was the information being requested.

I’ve re-installed the app a dozen times and gone through Splunk support who basically confirmed what I had already stated was an issue. Their concern was the index that was being created didn’t take in any information but we re-created that a couple different ways and still no success.

As for the Syslog connector, the app page says that IBM has this component but I have searched for it and have yet to find a link to it anywhere from IBM or the BigFix team. All I can say now is that app really pushes my buttons.


I am trying to implement this as well. Has anyone made any progress in getting syslogs from Bigfix?

So after not looking at the app for a couple months because it made my blood boil, it looks like it started pulling in the data that it was configured to grab. I’m not sure what my other team members have done recently to make it work because I none of them had touched it for a while but all of sudden, a little over a month ago, it started working.

I scheduled the python scripts to run and they worked as well. There is some pruning that may need to be done to ensure that the data you’re trying to grab actually exists in your deployment but the app does seem to work.

As for the syslog connector, my statement above stands.

Where are the syslogs actually located?

