Ansible role for managing the log forwarder using rsyslog and Splunk Universal Forwarder
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet d98ed58f05
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:28:29 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:48:53 +00:00
defaults feat(ci): added yamllint 2025-06-06 13:40:11 +02:00
handlers feat: initial commit 2025-05-06 10:58:34 +02:00
meta feat(meta): compress galaxy_info file 2025-05-28 07:29:04 +02:00
roles ci: migrate from gitlab ci to woodpecker 2026-05-15 14:31:01 +02:00
tasks chore: migrate bare ansible_* facts to ansible_facts[] syntax 2026-05-19 09:19:05 +02:00
templates fix: consisten inputs naming for splunk 2025-05-06 11:10:03 +02:00
vars feat: initial commit 2025-05-06 10:58:34 +02:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:23:45 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:23:50 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:23:50 +02:00
.gitignore feat: initial commit 2025-05-06 10:58:34 +02:00
.markdownlint-cli2.jsonc ci: migrate from gitlab ci to woodpecker 2026-05-15 14:31:01 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:01:52 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:28 +02:00
AGENTS.md chore: add AGENTS.md for opencode agents 2026-02-16 10:06:22 +01:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:15 +02:00
playbook.yaml chore(playbook): run galaxy install only on first host 2026-08-13 08:49:03 +02:00
readme.md docs: improve readme 2026-10-05 17:28:29 +02:00
renovate.json fix(ci): use central config 2025-06-17 17:57:57 +02:00

Ansible Role: Log Forwarder

Installs rsyslog as a UDP syslog receiver and the Splunk Universal Forwarder, which ships the received logs from a tmpfs-backed /var/log/remote directory to a Splunk indexer.

Requirements

Debian-family hosts only (the install tasks use apt and are guarded by os_family == "Debian"). The role needs root (become: true) and a systemd-based host.

Dependencies

None (dependencies: []). The playbook installs this role (log_forwarder) from roles/requirements.yml.

Variables

Variable Required Default Description
splunk_forwarder_deb No Splunk Universal Forwarder 9.4.2 amd64 DEB on download.splunk.com URL of the Splunk Universal Forwarder package

Example

splunk_forwarder_deb: "https://download.splunk.com/products/universalforwarder/releases/9.4.2/linux/splunkforwarder-9.4.2-e9664af3d956-linux-amd64.deb"

Usage

Run playbook.yaml via Semaphore. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml on the controller and then includes the log_forwarder role on all hosts.

What it does

  • Installs rsyslog and enables a UDP listener on port 514 (/etc/rsyslog.d/incoming-udp514.conf).
  • Creates a var-log-remote.mount systemd unit that mounts a 512M tmpfs on /var/log/remote.
  • Adds /etc/logrotate.d/remote-tmpfs.conf (*.log, 10M, daily, copytruncate, no history kept) and a root cron job that forces this logrotate every 15 minutes.
  • Installs the Splunk Universal Forwarder DEB and writes inputs.conf and outputs.conf under /opt/splunkforwarder/etc/system/local/.
  • Monitors /var/log/remote (sourcetype = syslog, index = default, host_segment = 3) and forwards to 100.64.0.10:9997. The indexer address is hardcoded in templates/splunkforwarder/outputs.conf.j2.
  • Handlers restart rsyslog and SplunkForwarder.service when their configuration changes.