<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CEF output forwarding everything from all indexes and sources in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/CEF-output-forwarding-everything-from-all-indexes-and-sources/m-p/298394#M35638</link>
    <description>&lt;OL&gt;
&lt;LI&gt;HF's&lt;/LI&gt;
&lt;LI&gt;Yes, cooked&lt;/LI&gt;
&lt;LI&gt;Maybe you can.  We do not push apps to our indexers in that we do not as a normal routine install apps unless absolutely necessary/required.&lt;BR /&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Certain the installation method or process has nothing to do with this problem&lt;/P&gt;</description>
    <pubDate>Mon, 03 Jul 2017 01:50:39 GMT</pubDate>
    <dc:creator>tlmayes</dc:creator>
    <dc:date>2017-07-03T01:50:39Z</dc:date>
    <item>
      <title>CEF output forwarding everything from all indexes and sources</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/CEF-output-forwarding-everything-from-all-indexes-and-sources/m-p/298391#M35635</link>
      <description>&lt;P&gt;Trying to configure Splunk App for CEF 2.0 on Splunk 6.5.2.  Our environment has clustered IDX's, and clustered SH's.  I have combed the documents and installed, configured and deployed appropriately, but have missed some detail that I cannot discover. &lt;/P&gt;

&lt;P&gt;Went thorough the process of creating a datamodel/dataset, on the clustered SH's, and then proceeded to deploy these using the App for CEF.  Then installed the downloaded .spl file to (1) indexer in the cluster for testing.  The receiver (destination for the CEF output) now receives 100% of all events.  No filtering is occurring.&lt;/P&gt;

&lt;P&gt;Built a single stand-alone server to look just like the production environment.  Same index, apps, Datamodel, &amp;amp; Dataset.  Only difference is that there is no system separation as in a clustered/peer model.  The same receiver now receives ONLY the events outlined in the datamodel/dataset.&lt;/P&gt;

&lt;P&gt;Stuck (and obviously missing something)&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 13:31:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/CEF-output-forwarding-everything-from-all-indexes-and-sources/m-p/298391#M35635</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2017-05-17T13:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: CEF output forwarding everything from all indexes and sources</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/CEF-output-forwarding-everything-from-all-indexes-and-sources/m-p/298392#M35636</link>
      <description>&lt;P&gt;45 days now working with Splunk support on this issue, and no resolution.&lt;BR /&gt;&lt;BR /&gt;
Has anybody got this app to work in a clustered IDX/SH environment, and been able to do so more than once?  Is easy to get it to work on a single server, but not in a clustered environment.  &lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 17:27:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/CEF-output-forwarding-everything-from-all-indexes-and-sources/m-p/298392#M35636</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2017-06-30T17:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: CEF output forwarding everything from all indexes and sources</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/CEF-output-forwarding-everything-from-all-indexes-and-sources/m-p/298393#M35637</link>
      <description>&lt;P&gt;hi mate, just to double check..&lt;BR /&gt;&lt;BR /&gt;
1. do you have Heavy forwarders  or UF  sending the data to your cluster?&lt;BR /&gt;
2. Is the raw events cooked before it reaches Indexers?&lt;BR /&gt;
3. Why you installing spl file in the indexer directly? I thought you have to push via cluster master-apps to indexer slaves&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jul 2017 09:25:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/CEF-output-forwarding-everything-from-all-indexes-and-sources/m-p/298393#M35637</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2017-07-01T09:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: CEF output forwarding everything from all indexes and sources</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/CEF-output-forwarding-everything-from-all-indexes-and-sources/m-p/298394#M35638</link>
      <description>&lt;OL&gt;
&lt;LI&gt;HF's&lt;/LI&gt;
&lt;LI&gt;Yes, cooked&lt;/LI&gt;
&lt;LI&gt;Maybe you can.  We do not push apps to our indexers in that we do not as a normal routine install apps unless absolutely necessary/required.&lt;BR /&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Certain the installation method or process has nothing to do with this problem&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2017 01:50:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/CEF-output-forwarding-everything-from-all-indexes-and-sources/m-p/298394#M35638</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2017-07-03T01:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: CEF output forwarding everything from all indexes and sources</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/CEF-output-forwarding-everything-from-all-indexes-and-sources/m-p/298395#M35639</link>
      <description>&lt;P&gt;Solution to the problem.  Finally got support engineers on the phone.  Discovered bug in the code, and an erroneous setting in one of the indexers outputs.conf.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2017 14:11:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/CEF-output-forwarding-everything-from-all-indexes-and-sources/m-p/298395#M35639</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2017-07-25T14:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: CEF output forwarding everything from all indexes and sources</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/CEF-output-forwarding-everything-from-all-indexes-and-sources/m-p/298396#M35640</link>
      <description>&lt;P&gt;After testing, seems the "fix" for the bug didn't work.  CEF forwarding v2.0 &amp;amp; v2.0.1 does not work, even with developer support, on what I consider to be a simple deployment&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2017 00:34:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/CEF-output-forwarding-everything-from-all-indexes-and-sources/m-p/298396#M35640</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2017-11-20T00:34:05Z</dc:date>
    </item>
  </channel>
</rss>

