<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remove or disable the additional syslog header when using forwarding in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Remove-or-disable-the-additional-syslog-header-when-using/m-p/697123#M20029</link>
    <description>&lt;P&gt;Please feel free to share your current outsputs.conf.&lt;/P&gt;&lt;P&gt;If you use the [syslog] stanza to forward the data to your third-party system no additional header should be added by splunk.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.3.0/Forwarding/Forwarddatatothird-partysystemsd#Syslog_data" target="_blank"&gt;Forward data to third-party systems - Splunk Documentation&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Aug 2024 09:12:39 GMT</pubDate>
    <dc:creator>PaulPanther</dc:creator>
    <dc:date>2024-08-23T09:12:39Z</dc:date>
    <item>
      <title>Remove or disable the additional syslog header when using forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Remove-or-disable-the-additional-syslog-header-when-using/m-p/697121#M20028</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am currently dealing with some logs being forwarded via syslog to a third party system. The question is if there is an option to prevent splunk from adding an additional header to each message before it is forwarded. So there should be a way to disable the additional syslog header when using forwarding, so that the third party system receives the original message by removing the header.&lt;/P&gt;&lt;P&gt;Any ideas, can you give me a practical example?&lt;BR /&gt;I am trying to test by modifying the outputs.conf.&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks,&lt;BR /&gt;&lt;BR /&gt;Giulia&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 08:54:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Remove-or-disable-the-additional-syslog-header-when-using/m-p/697121#M20028</guid>
      <dc:creator>giulia_casaldi</dc:creator>
      <dc:date>2024-08-23T08:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: Remove or disable the additional syslog header when using forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Remove-or-disable-the-additional-syslog-header-when-using/m-p/697123#M20029</link>
      <description>&lt;P&gt;Please feel free to share your current outsputs.conf.&lt;/P&gt;&lt;P&gt;If you use the [syslog] stanza to forward the data to your third-party system no additional header should be added by splunk.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.3.0/Forwarding/Forwarddatatothird-partysystemsd#Syslog_data" target="_blank"&gt;Forward data to third-party systems - Splunk Documentation&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 09:12:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Remove-or-disable-the-additional-syslog-header-when-using/m-p/697123#M20029</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2024-08-23T09:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: Remove or disable the additional syslog header when using forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Remove-or-disable-the-additional-syslog-header-when-using/m-p/697129#M20030</link>
      <description>&lt;P&gt;hello &amp;nbsp;, this is the current example of the outputs.conf, but still the header is not gone:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[tcpout-server://xxxx..xxx:9997][tcpout-server://yyy.yyy.yyy:9997]

[tcpout-server://zz.zzz.zzz:9997]





[tcpout:default-autolb-group]
server = xx.xxx.xxx:9997,yyy.yyy.yyy:9997,zz.zzz.zzz:9997
disabled = false



[syslog]
#defaultGroup = syslogGroup2



[syslog:syslogGroup1]
server = aa.aaa.aa.a.:514
type = udp
syslogSourceType = fortigate



[syslog:syslogGroup2]
server = bb.bbb.bbb:517
type = udp
syslogSourceType = fortigate&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;can you give me an example of how i could fix it?&lt;/P&gt;
&lt;P&gt;Thank you very much&lt;/P&gt;
&lt;P&gt;Giulia&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 10:54:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Remove-or-disable-the-additional-syslog-header-when-using/m-p/697129#M20030</guid>
      <dc:creator>giulia_casaldi</dc:creator>
      <dc:date>2024-08-23T10:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: Remove or disable the additional syslog header when using forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Remove-or-disable-the-additional-syslog-header-when-using/m-p/697132#M20031</link>
      <description>&lt;P&gt;Please check the syslogSourceType and reconfigure it&lt;/P&gt;&lt;PRE&gt;syslogSourceType = &amp;lt;string&amp;gt;
* Specifies an additional rule for handling data, in addition to that
  provided by the 'syslog' source type.
* This string is used as a substring match against the sourcetype key. For
  example, if the string is set to "syslog", then all sourcetypes
  containing the string 'syslog' receive this special treatment.
* To match a sourcetype explicitly, use the pattern
  "sourcetype::sourcetype_name".
    * Example: syslogSourceType = sourcetype::apache_common
* Data that is "syslog" or matches this setting is assumed to already be in
  syslog format.
* Data that does not match the rules has a header, optionally a timestamp
  (if defined in 'timestampformat'), and a hostname added to the front of
  the event. This is how Splunk software causes arbitrary log data to match syslog expectations.
* No default.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.3.0/Admin/Outputsconf" target="_blank"&gt;outputs.conf - Splunk Documentation&lt;/A&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 10:41:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Remove-or-disable-the-additional-syslog-header-when-using/m-p/697132#M20031</guid>
      <dc:creator>PaulPanther</dc:creator>
      <dc:date>2024-08-23T10:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Remove or disable the additional syslog header when using forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Remove-or-disable-the-additional-syslog-header-when-using/m-p/697143#M20033</link>
      <description>&lt;P&gt;identifying the correct sourcetype removed only one part of the header, still however it does not remove the priority and the other part of the header...&lt;BR /&gt;I had already tried that.&lt;BR /&gt;I thank you, do you have any other solutions?&lt;BR /&gt;Thank you,&lt;BR /&gt;&lt;BR /&gt;Giulia&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 12:35:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Remove-or-disable-the-additional-syslog-header-when-using/m-p/697143#M20033</guid>
      <dc:creator>giulia_casaldi</dc:creator>
      <dc:date>2024-08-23T12:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Remove or disable the additional syslog header when using forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Remove-or-disable-the-additional-syslog-header-when-using/m-p/698084#M20128</link>
      <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;i found the solution with my team:&lt;BR /&gt;In addition to changing the output.conf by inserting the appropriate sourcetype.&lt;BR /&gt;the moment the header is still not removed we followed this procedure:&lt;BR /&gt;by going to change the following template definition of the rsyslog file on all UFs, removing %TIMESTAMP% %HOSTNAME% (the one that appears in the header) within the configuration.&lt;BR /&gt;&lt;BR /&gt;bye,&lt;BR /&gt;&lt;BR /&gt;G.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 14:53:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Remove-or-disable-the-additional-syslog-header-when-using/m-p/698084#M20128</guid>
      <dc:creator>giulia_casaldi</dc:creator>
      <dc:date>2024-09-03T14:53:13Z</dc:date>
    </item>
  </channel>
</rss>

