Ansible role for managing the log forwarder using rsyslog and Splunk Universal Forwarder
- Jinja 100%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| defaults | ||
| handlers | ||
| meta | ||
| roles | ||
| tasks | ||
| templates | ||
| vars | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| AGENTS.md | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
Ansible Role: Log Forwarder
Installs rsyslog as a UDP syslog receiver and the Splunk Universal Forwarder, which ships the received logs
from a tmpfs-backed /var/log/remote directory to a Splunk indexer.
Requirements
Debian-family hosts only (the install tasks use apt and are guarded by os_family == "Debian"). The role needs
root (become: true) and a systemd-based host.
Dependencies
None (dependencies: []). The playbook installs this role (log_forwarder) from roles/requirements.yml.
Variables
| Variable | Required | Default | Description |
|---|---|---|---|
splunk_forwarder_deb |
No | Splunk Universal Forwarder 9.4.2 amd64 DEB on download.splunk.com |
URL of the Splunk Universal Forwarder package |
Example
splunk_forwarder_deb: "https://download.splunk.com/products/universalforwarder/releases/9.4.2/linux/splunkforwarder-9.4.2-e9664af3d956-linux-amd64.deb"
Usage
Run playbook.yaml via Semaphore. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml
on the controller and then includes the log_forwarder role on all hosts.
What it does
- Installs
rsyslogand enables a UDP listener on port 514 (/etc/rsyslog.d/incoming-udp514.conf). - Creates a
var-log-remote.mountsystemd unit that mounts a 512M tmpfs on/var/log/remote. - Adds
/etc/logrotate.d/remote-tmpfs.conf(*.log, 10M, daily,copytruncate, no history kept) and a root cron job that forces this logrotate every 15 minutes. - Installs the Splunk Universal Forwarder DEB and writes
inputs.confandoutputs.confunder/opt/splunkforwarder/etc/system/local/. - Monitors
/var/log/remote(sourcetype = syslog,index = default,host_segment = 3) and forwards to100.64.0.10:9997. The indexer address is hardcoded intemplates/splunkforwarder/outputs.conf.j2. - Handlers restart
rsyslogandSplunkForwarder.servicewhen their configuration changes.