<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk event forwarding in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-event-forwarding/m-p/103216#M7202</link>
    <description>&lt;P&gt;You can't grab events right from the raw index files. You need to go through the regular Splunk mechanisms, which the docs that kristian links to describe. Is there anything in particular that you're missing in the docs? Because I see instructions there on how to grab all or just a subset of the events and forward it to a 3rd party system over TCP...&lt;/P&gt;</description>
    <pubDate>Tue, 23 Apr 2013 09:19:52 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2013-04-23T09:19:52Z</dc:date>
    <item>
      <title>Splunk event forwarding</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-event-forwarding/m-p/103213#M7199</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
I have tried to forward log event stored in splunk to Linux machine via syslog.&lt;BR /&gt;
but only splunk specific events (means events that are generated by splunk not the stored events) are forwarded to linux machine.&lt;BR /&gt;
can anybody please tell me about process of forwarding stored events from splunk to other linux/windows box.?? please&lt;/P&gt;

&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2013 17:01:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-event-forwarding/m-p/103213#M7199</guid>
      <dc:creator>shaileshpawar21</dc:creator>
      <dc:date>2013-04-22T17:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event forwarding</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-event-forwarding/m-p/103214#M7200</link>
      <description>&lt;P&gt;You can forward incoming events to a third party system (i.e. a non-splunk system). From the wording of your question it seems like you have set this up with partial success. I believe that you wish to forward data that has already been indexed by a splunk indexer. To the best of my knowledge that is not as straightforward as it might seem, unfortunately. Once event have been indexed (i.e. you don't forward the incoming stream of events), you'll have make searches and export the search results.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Forwarddatatothird-partysystemsd"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Forwarddatatothird-partysystemsd&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Knowledge/Savingsearchesandsharingsearchresults"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/Knowledge/Savingsearchesandsharingsearchresults&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/answers/46050/export-raw-logs-from-specific-time"&gt;http://splunk-base.splunk.com/answers/46050/export-raw-logs-from-specific-time&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;Kristian&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2013 18:59:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-event-forwarding/m-p/103214#M7200</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-04-22T18:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event forwarding</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-event-forwarding/m-p/103215#M7201</link>
      <description>&lt;P&gt;Thanks Kristian,&lt;BR /&gt;
I want to forward data(events) which is stored in index(journal.gz file) to the remote on third party non splunk machine via TCP port through syslog.&lt;BR /&gt;
How should I do that ?&lt;BR /&gt;
Please help me in this.&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 08:44:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-event-forwarding/m-p/103215#M7201</guid>
      <dc:creator>shaileshpawar21</dc:creator>
      <dc:date>2013-04-23T08:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event forwarding</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-event-forwarding/m-p/103216#M7202</link>
      <description>&lt;P&gt;You can't grab events right from the raw index files. You need to go through the regular Splunk mechanisms, which the docs that kristian links to describe. Is there anything in particular that you're missing in the docs? Because I see instructions there on how to grab all or just a subset of the events and forward it to a 3rd party system over TCP...&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 09:19:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-event-forwarding/m-p/103216#M7202</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-04-23T09:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk event forwarding</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-event-forwarding/m-p/103217#M7203</link>
      <description>&lt;P&gt;Hi Ayn,&lt;/P&gt;

&lt;P&gt;I have followed all steps given in link but events are not forwarded to other machine.&lt;BR /&gt;
I have done following steps.&lt;BR /&gt;
1st received events from TCP port&lt;BR /&gt;
then in foward made the configuration of hostname:port&lt;BR /&gt;
the host which is mentioned has beed configured to read events through syslog. (for this edited rsyslog.conf)&lt;BR /&gt;
but events are not present in log file of other machine..&lt;BR /&gt;
Please help me,&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2013 09:40:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-event-forwarding/m-p/103217#M7203</guid>
      <dc:creator>shaileshpawar21</dc:creator>
      <dc:date>2013-04-24T09:40:10Z</dc:date>
    </item>
  </channel>
</rss>

