<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Symantec Data Loss Prevention (DLP): How to specify a certain index for events from a Syslog host? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Symantec-Data-Loss-Prevention-DLP-How-to-specify-a-certain-index/m-p/177389#M17279</link>
    <description>&lt;P&gt;Welcome to Splunk! Good question.. &lt;/P&gt;

&lt;P&gt;You can find what you are looking for here.&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/1090/how-do-i-forward-data-to-a-specific-index.html"&gt;http://answers.splunk.com/answers/1090/how-do-i-forward-data-to-a-specific-index.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Aug 2015 18:28:22 GMT</pubDate>
    <dc:creator>shandman</dc:creator>
    <dc:date>2015-08-18T18:28:22Z</dc:date>
    <item>
      <title>Symantec Data Loss Prevention (DLP): How to specify a certain index for events from a Syslog host?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Symantec-Data-Loss-Prevention-DLP-How-to-specify-a-certain-index/m-p/177388#M17278</link>
      <description>&lt;P&gt;Newcomer to Splunk, just took the "Using Splunk" course and trying to learn how all of the pieces fit together.&lt;/P&gt;

&lt;P&gt;I installed the Symantec DLP application, and set it up according to the documentation.  It uses syslog to send events (incidents) into Splunk.  I just got a couple of Events to show up in Splunk, so that's exciting!&lt;/P&gt;

&lt;P&gt;However, it appears that the App is only looking for them in a "dlp" index.  These events are coming into my "main" index.  How do I map that all events logged via this host should go into a "dlp" index?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 18:18:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Symantec-Data-Loss-Prevention-DLP-How-to-specify-a-certain-index/m-p/177388#M17278</guid>
      <dc:creator>pickerin</dc:creator>
      <dc:date>2015-08-18T18:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec Data Loss Prevention (DLP): How to specify a certain index for events from a Syslog host?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Symantec-Data-Loss-Prevention-DLP-How-to-specify-a-certain-index/m-p/177389#M17279</link>
      <description>&lt;P&gt;Welcome to Splunk! Good question.. &lt;/P&gt;

&lt;P&gt;You can find what you are looking for here.&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/1090/how-do-i-forward-data-to-a-specific-index.html"&gt;http://answers.splunk.com/answers/1090/how-do-i-forward-data-to-a-specific-index.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 18:28:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Symantec-Data-Loss-Prevention-DLP-How-to-specify-a-certain-index/m-p/177389#M17279</guid>
      <dc:creator>shandman</dc:creator>
      <dc:date>2015-08-18T18:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec Data Loss Prevention (DLP): How to specify a certain index for events from a Syslog host?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Symantec-Data-Loss-Prevention-DLP-How-to-specify-a-certain-index/m-p/177390#M17280</link>
      <description>&lt;P&gt;This is a great solution if you have a forwarder that you're using.&lt;BR /&gt;
Unfortunately, I have an appliance that is sending syslog data on UDP 514 to the Indexer.&lt;BR /&gt;
So, I'm looking for a solution that can be implemented on the Indexer only.&lt;/P&gt;

&lt;P&gt;I guess I could create a custom index that listens on and accepts syslog from a unique port, then assign that port the index, but I was hoping for something a little more straightforward (as that solution also requires changing firewalls to open up additional ports).&lt;/P&gt;

&lt;P&gt;I was hoping that I could just map the hostname to a specific index, as that hostname is never forwarding anything for a different index.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 21:11:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Symantec-Data-Loss-Prevention-DLP-How-to-specify-a-certain-index/m-p/177390#M17280</guid>
      <dc:creator>pickerin</dc:creator>
      <dc:date>2015-08-18T21:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Symantec Data Loss Prevention (DLP): How to specify a certain index for events from a Syslog host?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Symantec-Data-Loss-Prevention-DLP-How-to-specify-a-certain-index/m-p/177391#M17281</link>
      <description>&lt;P&gt;Answer:  The only solution if you wish to send the data directly to the indexer is to do so on a custom port, so you can specific a unique index and sourcetype.  &lt;/P&gt;

&lt;P&gt;Solution:  I moved the logs to the syslog aggregator, where I could monitor the path and provide a unique index and sourcetype, then that host is a universal forwarder to the index.  Works great (but requires two systems).&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 12:09:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Symantec-Data-Loss-Prevention-DLP-How-to-specify-a-certain-index/m-p/177391#M17281</guid>
      <dc:creator>pickerin</dc:creator>
      <dc:date>2015-10-02T12:09:04Z</dc:date>
    </item>
  </channel>
</rss>

