<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.thread@place:occasion</title>
    <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/655069#M49</link>
    <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Hey Everyone,&lt;/P&gt;&lt;P&gt;Don't forget to submit your questions at registration! You can also post a comment here for any topics you'd like to see discussed in the Community Office Hours session, or&amp;nbsp;head to&amp;nbsp;the&amp;nbsp;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;#office-hours&lt;/A&gt;&amp;nbsp;user Slack channel to ask questions and join the discussion&lt;EM&gt; (request access&amp;nbsp;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener nofollow noreferrer"&gt;here&lt;/A&gt;).&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 21 Aug 2023 18:01:17 GMT</pubDate>
    <dc:creator>adepp</dc:creator>
    <dc:date>2023-08-21T18:01:17Z</dc:date>
    <item>
      <title>Getting Data In: Forwarders &amp; Edge Processor - Wed 8/23/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/652617#M41</link>
      <description>&lt;P&gt;&lt;SPAN&gt;[1pm PT / 4pm ET] -&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunk.zoom.us/meeting/register/tJYvcuGtqTgsE9BtB4MbKSKETh-t8pR6lCoH" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Register here&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt; and ask questions below. This thread is for the Community Office Hours session on &lt;/SPAN&gt;&lt;STRONG&gt;Getting Data In (GDI): Forwarders &amp;amp; Edge Processor &lt;/STRONG&gt;&lt;SPAN&gt;on &lt;/SPAN&gt;&lt;STRONG&gt;Wed, August 23, 2023 at 1pm PT / 4pm ET.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is your opportunity to ask questions related to getting data into Splunk Platform using forwarders or Splunk Edge Processor. Including:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Universal forwarder or heavy forwarder setup and troubleshooting&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Forwarder connectivity issues, blocked queues, and tuning&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Using Edge Processor&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Forwarders vs. Edge Processor vs. Ingest Actions&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Anything else you’d like to learn!&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please submit your questions at registration or as comments below.&lt;/STRONG&gt;&lt;SPAN&gt; You can also head to &lt;/SPAN&gt;&lt;SPAN&gt;the &lt;/SPAN&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;#office-hours&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; user Slack channel to ask questions (request access &lt;/SPAN&gt;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Pre-submitted questions will be prioritized&lt;/STRONG&gt;&lt;SPAN&gt;. After that, we will go in order of the questions posted below, then will open the floor up to live Q&amp;amp;A with meeting participants. If there’s a quick answer available, we’ll post as a direct reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Look forward to connecting!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 21:12:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/652617#M41</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-08-24T21:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Forwarders &amp; Edge Processor - Wed 8/23/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/655069#M49</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Hey Everyone,&lt;/P&gt;&lt;P&gt;Don't forget to submit your questions at registration! You can also post a comment here for any topics you'd like to see discussed in the Community Office Hours session, or&amp;nbsp;head to&amp;nbsp;the&amp;nbsp;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;#office-hours&lt;/A&gt;&amp;nbsp;user Slack channel to ask questions and join the discussion&lt;EM&gt; (request access&amp;nbsp;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener nofollow noreferrer"&gt;here&lt;/A&gt;).&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 21 Aug 2023 18:01:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/655069#M49</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-08-21T18:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Forwarders &amp; Edge Processor - Wed 8/23/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/655236#M50</link>
      <description>&lt;P&gt;First off, thanks so much for putting this together!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;My main issue so far with the EP is configuring TLS to work when performing the initial configuration of a processor.&amp;nbsp; According to the documentation I can use the Splunk Forwarder certs that I downloaded from the Splunk Cloud platform and place them in the Server Key/Server Cert/CA Cert sections of the Edge Processor config.&amp;nbsp; There are two problems I run into when I do this:&lt;BR /&gt;&lt;BR /&gt;1. I get the error -&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;There was a problem creating your new Edge Processor.&lt;/P&gt;&lt;P&gt;INVALID_SERVER_PK_PEM_FORMAT (I can confirm that the files are in PEM format)&lt;BR /&gt;&lt;BR /&gt;2. The other issue is (I think) that the outputs.conf would need to be updated to reflect the architecture change (UF/HEC -&amp;gt; Splunk Cloud to UF/HEC -&amp;gt; EP -&amp;gt; Splunk Cloud).&amp;nbsp; Would that be done after the cert config is completed?&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 22 Aug 2023 22:00:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/655236#M50</guid>
      <dc:creator>splunkzilla</dc:creator>
      <dc:date>2023-08-22T22:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Forwarders &amp; Edge Processor - Wed 8/23/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/655409#M51</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Expert Solution:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;Occurs because the private key is formatted incorrectly for a private key PEM. &amp;nbsp; The file must be in correct PEM format and correctly tagged as a private key in the header and footer.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Yes, certs need to be updated in the output.conf file.&amp;nbsp; This can be done before or after EP has be updated.&amp;nbsp; Data will not be received until both are updated.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Wed, 23 Aug 2023 22:05:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/655409#M51</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-08-23T22:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Forwarders &amp; Edge Processor - Wed 8/23/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/655410#M52</link>
      <description>&lt;P&gt;Thank you!&amp;nbsp; I did discover before the session began that the issue was related to a number of intermediate certs contained in the PEM file.&amp;nbsp; Once I removed those the import worked properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 22:08:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/655410#M52</guid>
      <dc:creator>splunkzilla</dc:creator>
      <dc:date>2023-08-23T22:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Forwarders &amp; Edge Processor - Wed 8/23/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/655546#M53</link>
      <description>&lt;P&gt;Great! Glad you figured it out. I also posted the session recording in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;#office-hours&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;if you'd like to rewatch the experts talk through it. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Baylie&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 20:57:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/655546#M53</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-08-24T20:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Forwarders &amp; Edge Processor - Wed 8/23/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/655552#M54</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Here are a few questions from the session (get the full Q&amp;amp;A deck and live recording in the &lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;SPAN&gt;#office-hours&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;Slack channel)&lt;/SPAN&gt;:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Q1:&amp;nbsp;Can Forwarder be on the same server as Splunk?&amp;nbsp; Do you need forwarders for security monitoring?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Yes, you can multi-tenant a UF with another instance, but it's not advised due to resource contention.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Strictly speaking, no, you don't need forwarders for security monitoring. While not strictly required, forwarders improve real-time data collection, helping in timely security monitoring.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q2: How do you ingest logs from linux auditd into your Splunk app for processing?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The simplest solution is often the best! &lt;A href="https://splunkbase.splunk.com/app/833" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/833&lt;/A&gt;&amp;nbsp;(or Splunk Add-On for Unix/Linux)&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;followed by…&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Linux/Configure4" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/AddOns/released/Linux/Configure4&lt;/A&gt;&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;If you do the above but don’t see data, check the troubleshooting step in the same doc for a helpful tip when using TCP protocol:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Linux/Troubleshoot#Audit_data_not_collected" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/AddOns/released/Linux/Troubleshoot#Audit_data_not_collected&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;There are 3rd party solutions available as well though we cannot endorse them. As with all things, test in a small isolated instance before deploying any new configuration to a larger environment!&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q3: Why am I having blocked queues?&amp;nbsp;How do I troubleshoot blocked queues that are preventing data from being indexed?&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The short answer is usually either a bottleneck or a failure in the pipeline. The longer answer can be a bit more complicated.&lt;BR /&gt;First you want to identify where the blockage originates!&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Like a river with a dam, always follow it downstream until you find the obstruction. Using ‘metrics.log (blocked=true)’ as your guide, this means start from the Indexer’s queues and work your way backwards first. Then once the instance is identified, narrow it down to a specific queue.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Once you find the queue that is affected, the troubleshooting steps can vary particularly heavily. Here’s some examples by blocked queue type:&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Parsing: Check for new data that may not have proper encoding, headers or linebreak rules. splunkd.log can help!&lt;/LI&gt;&lt;LI&gt;AggQueue: Check for bad date/time or bad extractions for date/time and any MUST_BREAK rules.&lt;/LI&gt;&lt;LI&gt;Typing: Regex, regex, regex….usually. New data with new extractions? Too many .*’s in that regex pattern? Regex Profile can help here too!&lt;/LI&gt;&lt;LI&gt;Index: Usually throughput or network/OS configuration at play here but could be any number of possibilities. splunkd.log is your best friend with this one!&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q4: What’s the difference between "search in" vs "search IN"?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Short answer: they are the same thing but made distinct because of which command precedes them. This is referenced in the following sections of our documentation:&lt;UL&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/ConditionalFunctions#in.28.26lt.3Bfield.26gt.3B.2C.26lt.3Blist.26gt.3B.29" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;“in(&amp;lt;field&amp;gt;,&amp;lt;list&amp;gt;)”&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt; refers to its use (in lowercase) as part of the ‘where’ or ‘eval’ commands, for example.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/Search#Multiple_field-value_comparisons_with_the_IN_operator" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;“Multiple field-value comparisons with the IN operator”&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt; refers to its use (in uppercase) in the ‘search’ or ‘tstats’ command function as a comparison operator.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Syntactically, SPL will alert you to the validity of your case choice based on the command within which it is contained and the attached modifiers and lists though, typically, these are the rules:&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;IN (“field1”,”field2”) is valid for search and tstats&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;in(field1,field2) is valid for where, eval and fieldstats&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q5: How do you configure Edge Processor servers and where? In cloud or in our HF(LAN)?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/EdgeProcessor/CreateNode" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/EdgeProcessor/CreateNode&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;OR&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/EdgeProcessor/QuickStart" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/EdgeProcessor/QuickStart&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;The configuration of each node happens on your environment locally but can be managed all from the Cloud Platform!&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Q6: How can I set up Edge Processor as a service?&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We’ve got you covered with instructions for configuring systemd upon installation here: &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.0.2305/EdgeProcessor/CreateNode#Install_an_instance_and_configure_systemd" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.0.2305/EdgeProcessor/CreateNode#Install_an_instance_and_configure_systemd&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Other Questions (check the &lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;#office-hours&lt;/A&gt;&amp;nbsp;Slack channel for responses):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is Edge Processor available today and who can use it?&lt;/LI&gt;&lt;LI&gt;How do I access Edge Processor?&lt;/LI&gt;&lt;LI&gt;Why do I need a Forwarder?&lt;/LI&gt;&lt;LI&gt;How can I get Windows internal logging (wineventlog) only starting from the time that I startup the Windows UF and NOT all historical, so I don’t exceed licensing?&lt;/LI&gt;&lt;LI&gt;Installing a universal forwarder that doesn't have connectivity to a deployment server. What do I need to copy from a host that was deployed by the deployment server? This is Splunk Cloud&lt;/LI&gt;&lt;LI&gt;Edge Processor overview&lt;/LI&gt;&lt;LI&gt;Edge Processor demo videos&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 24 Aug 2023 21:12:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/655552#M54</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-08-24T21:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Forwarders &amp; Edge Processor - Wed 8/23/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/678179#M84</link>
      <description>&lt;P&gt;Hello, I would like to have access to the video in&amp;nbsp;&lt;A href="https://splunk-usergroups.slack.com/" target="_blank"&gt;https://splunk-usergroups.slack.com/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 11:59:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Forwarders-amp-Edge-Processor-Wed-8-23-23/ec-p/678179#M84</guid>
      <dc:creator>adrifesa95</dc:creator>
      <dc:date>2024-02-21T11:59:05Z</dc:date>
    </item>
  </channel>
</rss>

