<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP Input or SQL for Websense Security Logs in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-Input-or-SQL-for-Websense-Security-Logs/m-p/163424#M15313</link>
    <description>&lt;P&gt;Since I have seen some posts that say that SQL Logs are the way to go, and TCP inputs have the possibility of losing data if the splunk server were to go down. I am going to say that the better way is through MSSQL as it will pick up where it left off.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Feb 2014 15:59:11 GMT</pubDate>
    <dc:creator>aelliott</dc:creator>
    <dc:date>2014-02-24T15:59:11Z</dc:date>
    <item>
      <title>TCP Input or SQL for Websense Security Logs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-Input-or-SQL-for-Websense-Security-Logs/m-p/163423#M15312</link>
      <description>&lt;P&gt;To feed logs from Websense to Splunk, which would be ideal and why?&lt;BR /&gt;
As a TCP Input&lt;BR /&gt;
From MSSQL&lt;/P&gt;

&lt;P&gt;If Splunk server goes down, will logs be lost using the TCP input?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2014 15:29:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-Input-or-SQL-for-Websense-Security-Logs/m-p/163423#M15312</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2014-02-24T15:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Input or SQL for Websense Security Logs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-Input-or-SQL-for-Websense-Security-Logs/m-p/163424#M15313</link>
      <description>&lt;P&gt;Since I have seen some posts that say that SQL Logs are the way to go, and TCP inputs have the possibility of losing data if the splunk server were to go down. I am going to say that the better way is through MSSQL as it will pick up where it left off.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2014 15:59:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/TCP-Input-or-SQL-for-Websense-Security-Logs/m-p/163424#M15313</guid>
      <dc:creator>aelliott</dc:creator>
      <dc:date>2014-02-24T15:59:11Z</dc:date>
    </item>
  </channel>
</rss>

