<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Having trouble to forward data to Kiwi syslog in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336121#M12552</link>
    <description>&lt;P&gt;cemiam,&lt;/P&gt;

&lt;P&gt;I am assuming that your setup goes syslog data&amp;gt;Kiwi syslog&amp;gt;Splunk. Is this correct? It look like the reason why you are getting this error is because the Splunk Heavy Forwarder cannot connect to the indexer. The typical setup for syslog would be to have Kiwi write this data to disk and have a Universal Forwarder pick up the readable file on disk and send it up to be indexed. Let me know either way.&lt;/P&gt;

&lt;P&gt;Here are some articles that might be of some use if you haven't seen them already:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/290158/how-do-i-send-data-from-kiwi-syslog-to-a-splunk-in.html"&gt;https://answers.splunk.com/answers/290158/how-do-i-send-data-from-kiwi-syslog-to-a-splunk-in.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/80134/what-is-the-easiest-way-to-get-data-from-a-kiwi-syslog-server-into-splunk.html"&gt;https://answers.splunk.com/answers/80134/what-is-the-easiest-way-to-get-data-from-a-kiwi-syslog-server-into-splunk.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Oct 2017 10:46:18 GMT</pubDate>
    <dc:creator>ncrisler</dc:creator>
    <dc:date>2017-10-27T10:46:18Z</dc:date>
    <item>
      <title>Having trouble to forward data to Kiwi syslog</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336120#M12551</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am trying forward data to Kiwi syslog. I have installed and configured a Heavy Forwarder and forward my syslog data to Heavy Forwarder. Then configured the HF to forward data to Kiwi syslog instance. However it is only forwarding cooked data and not forwarding the syslog data itself. I checked the network and it's all reachable. I have noticed below error. What should I do to overcome this issue?&lt;/P&gt;

&lt;P&gt;Error:&lt;/P&gt;

&lt;P&gt;Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group default-autolb-group has been blocked for 10 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;

&lt;P&gt;Best Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 09:43:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336120#M12551</guid>
      <dc:creator>cemiam</dc:creator>
      <dc:date>2017-10-27T09:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Having trouble to forward data to Kiwi syslog</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336121#M12552</link>
      <description>&lt;P&gt;cemiam,&lt;/P&gt;

&lt;P&gt;I am assuming that your setup goes syslog data&amp;gt;Kiwi syslog&amp;gt;Splunk. Is this correct? It look like the reason why you are getting this error is because the Splunk Heavy Forwarder cannot connect to the indexer. The typical setup for syslog would be to have Kiwi write this data to disk and have a Universal Forwarder pick up the readable file on disk and send it up to be indexed. Let me know either way.&lt;/P&gt;

&lt;P&gt;Here are some articles that might be of some use if you haven't seen them already:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/290158/how-do-i-send-data-from-kiwi-syslog-to-a-splunk-in.html"&gt;https://answers.splunk.com/answers/290158/how-do-i-send-data-from-kiwi-syslog-to-a-splunk-in.html&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/80134/what-is-the-easiest-way-to-get-data-from-a-kiwi-syslog-server-into-splunk.html"&gt;https://answers.splunk.com/answers/80134/what-is-the-easiest-way-to-get-data-from-a-kiwi-syslog-server-into-splunk.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 10:46:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336121#M12552</guid>
      <dc:creator>ncrisler</dc:creator>
      <dc:date>2017-10-27T10:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: Having trouble to forward data to Kiwi syslog</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336122#M12553</link>
      <description>&lt;P&gt;Hi ncrisler,&lt;/P&gt;

&lt;P&gt;Thanks for the response. Actually it is like Syslog data &amp;gt; Heavy Forwarder &amp;gt; Kiwi. I have also suspected about the connection problem but Heavy forwarder sends the cooked data. There might be a configuration issue. I am not sure if the Heavy Forwarder gets the syslog messages but it is listening port 9997 and I have checked the connection on the syslog source.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 10:55:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336122#M12553</guid>
      <dc:creator>cemiam</dc:creator>
      <dc:date>2017-10-27T10:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: Having trouble to forward data to Kiwi syslog</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336123#M12554</link>
      <description>&lt;P&gt;Hi cemiam, &lt;/P&gt;

&lt;P&gt;Can you please share your outputs.conf config?&lt;/P&gt;

&lt;P&gt;btool is a great command to get to know ;). run this from the cli of the HF:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;./splunk btool outputs list --debug&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.0/Troubleshooting/Usebtooltotroubleshootconfigurations"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.0/Troubleshooting/Usebtooltotroubleshootconfigurations&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also, I have to ask....why bother sending to an HF then kiwi?? I would probably look at either a) just adding kiwi as secondary syslog target on the devices, or 2) put kiwi in front of splunk and use a UF eat logs kiwi puts down on disk?&lt;/P&gt;

&lt;P&gt;As you are seeing, blocking of one of your outputs on the HF can affect the other....&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 11:35:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336123#M12554</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-10-27T11:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: Having trouble to forward data to Kiwi syslog</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336124#M12555</link>
      <description>&lt;P&gt;Hi mmodestino,&lt;/P&gt;

&lt;P&gt;It was requested for a specific purpose. I don't have enough detail but I think this should work fine with current configuration. You can find outputs.conf config below. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/opt/splunk/etc/system/default/outputs.conf               [syslog]
/opt/splunk/etc/system/default/outputs.conf               maxEventSize = 1024
/opt/splunk/etc/system/default/outputs.conf               priority = &amp;lt;13&amp;gt;
/opt/splunk/etc/system/default/outputs.conf               type = udp
/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf [tcpout]
/opt/splunk/etc/system/default/outputs.conf               ackTimeoutOnShutdown = 30
/opt/splunk/etc/system/default/outputs.conf               autoLBFrequency = 30
/opt/splunk/etc/system/default/outputs.conf               autoLBVolume = 0
/opt/splunk/etc/system/default/outputs.conf               blockOnCloning = true
/opt/splunk/etc/system/default/outputs.conf               blockWarnThreshold = 100
/opt/splunk/etc/system/default/outputs.conf               cipherSuite = ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256:AES128-SHA256:ECDH-ECDSA-AES256-GCM-SHA384:ECDH-ECDSA-AES128-GCM-SHA256:ECDH-ECDSA-AES256-SHA384:ECDH-ECDSA-AES128-SHA256
/opt/splunk/etc/system/default/outputs.conf               compressed = false
/opt/splunk/etc/system/default/outputs.conf               connectionTimeout = 20
/opt/splunk/etc/system/local/outputs.conf                 defaultGroup = default-autolb-group
/opt/splunk/etc/system/default/outputs.conf               disabled = false
/opt/splunk/etc/system/default/outputs.conf               dropClonedEventsOnQueueFull = 5
/opt/splunk/etc/system/default/outputs.conf               dropEventsOnQueueFull = -1
/opt/splunk/etc/system/default/outputs.conf               ecdhCurves = prime256v1, secp384r1, secp521r1
/opt/splunk/etc/system/default/outputs.conf               forceTimebasedAutoLB = false
/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf forwardedindex.0.whitelist = .*
/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf forwardedindex.1.blacklist = _.*
/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf forwardedindex.2.whitelist = (_audit|_introspection|_telemetry)
/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf forwardedindex.filter.disable = false
/opt/splunk/etc/system/default/outputs.conf               heartbeatFrequency = 30
/opt/splunk/etc/system/local/outputs.conf                 indexAndForward = 1
/opt/splunk/etc/system/default/outputs.conf               maxConnectionsPerIndexer = 2
/opt/splunk/etc/system/default/outputs.conf               maxFailuresPerInterval = 2
/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf maxQueueSize = 500KB
/opt/splunk/etc/system/default/outputs.conf               readTimeout = 300
/opt/splunk/etc/system/default/outputs.conf               secsInFailureInterval = 1
/opt/splunk/etc/system/default/outputs.conf               sendCookedData = true
/opt/splunk/etc/system/default/outputs.conf               sslQuietShutdown = false
/opt/splunk/etc/system/default/outputs.conf               sslVersions = tls1.2
/opt/splunk/etc/system/default/outputs.conf               tcpSendBufSz = 0
/opt/splunk/etc/system/default/outputs.conf               useACK = false
/opt/splunk/etc/system/default/outputs.conf               writeTimeout = 300
/opt/splunk/etc/system/local/outputs.conf                 [tcpout-server://10.19.1.xxx:514]
/opt/splunk/etc/system/local/outputs.conf                 [tcpout:default-autolb-group]
/opt/splunk/etc/system/local/outputs.conf                 disabled = false
/opt/splunk/etc/system/local/outputs.conf                 server = 10.19.1.xxx:514
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 27 Oct 2017 11:45:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336124#M12555</guid>
      <dc:creator>cemiam</dc:creator>
      <dc:date>2017-10-27T11:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: Having trouble to forward data to Kiwi syslog</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336125#M12556</link>
      <description>&lt;P&gt;I believe there's 2 things you can try here, &lt;/P&gt;

&lt;P&gt;1 : Use syslog output not TCP:&lt;BR /&gt;
 &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.0/Forwarding/Forwarddatatothird-partysystemsd#Syslog_data"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.0/Forwarding/Forwarddatatothird-partysystemsd#Syslog_data&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;It looks like you have configured a TCP instead of a syslog output. I believe I would go this route as it uses a separate output processor, which should ensure you don't impact any output going to splunk...although looking at this config, I dont see one, so might not be a concern for this HF.&lt;/P&gt;

&lt;P&gt;2: Update your TCP config to not send cooked data: &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.0/Forwarding/Forwarddatatothird-partysystemsd#TCP_data"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.0/Forwarding/Forwarddatatothird-partysystemsd#TCP_data&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [tcpout]

[tcpout:fastlane]
server = 10.1.1.35:6996
sendCookedData = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;While I hope this gets you rocking, I'd be questioning the design intent here, especially if we are catching udp from the input side on a port. If we are monitoring files...then I kind of get it....kind of.... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 11:59:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336125#M12556</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-10-27T11:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: Having trouble to forward data to Kiwi syslog</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336126#M12557</link>
      <description>&lt;P&gt;Hi mmodestino,&lt;/P&gt;

&lt;P&gt;Many thanks for the response. Soon I have started get logs. I have also getting audit logs. I have added sendCookedData = false parameter on [tcpout:fastlane] stanza. Do you have idea why is it still sending the audit logs?&lt;/P&gt;

&lt;P&gt;Best Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 13:23:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336126#M12557</guid>
      <dc:creator>cemiam</dc:creator>
      <dc:date>2017-10-27T13:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: Having trouble to forward data to Kiwi syslog</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336127#M12558</link>
      <description>&lt;P&gt;yeah because of &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf [tcpout]
.....
.....
     /opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf forwardedindex.2.whitelist = (_audit|_introspection|_telemetry)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Those inputs are whitelisted by default. You can disable the inputs or just remove them from the whitelist. &lt;/P&gt;

&lt;P&gt;I would also advise you try flipping over to syslog, as it wont have that settings...is there a reason you are remaining on tcp?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/opt/splunk/etc/system/default/outputs.conf               [syslog]
 /opt/splunk/etc/system/default/outputs.conf               maxEventSize = 1024
 /opt/splunk/etc/system/default/outputs.conf               priority = &amp;lt;13&amp;gt;
 /opt/splunk/etc/system/default/outputs.conf               type = udp
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 27 Oct 2017 14:38:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336127#M12558</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-10-27T14:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: Having trouble to forward data to Kiwi syslog</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336128#M12559</link>
      <description>&lt;P&gt;I am still having trouble to disable audit logs. You can find the btool commands output below. Do you have any idea why am I still getting the audit logs?&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf [syslog]&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf                 defaultGroup = syslogG                                                                                                             roup&lt;BR /&gt;
/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf forwardedindex.0.white                                                                                                             list = .*&lt;BR /&gt;
/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf forwardedindex.1.black                                                                                                             list = _.*&lt;BR /&gt;
/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf forwardedindex.filter.                                                                                                             disable = false&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               maxEventSize = 1024&lt;BR /&gt;
/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf maxQueueSize = 500KB&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               priority = &amp;lt;13&amp;gt;&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               type = udp&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf                 [syslog:syslogGroup]&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf                 sendCookedData = false&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf                 server = 10.19.1.158:1                                                                                                             514&lt;BR /&gt;
/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf [tcpout]&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               ackTimeoutOnShutdown =                                                                                                              30&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               autoLBFrequency = 30&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               autoLBVolume = 0&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               blockOnCloning = true&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               blockWarnThreshold = 1                                                                                                             00&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               cipherSuite = ECDHE-EC                                                                                                             DSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:                                                                                                             ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:EC                                                                                                             DHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA                                                                                                             256:AES128-SHA256:ECDH-ECDSA-AES256-GCM-SHA384:ECDH-ECDSA-AES128-GCM-SHA256:ECDH                                                                                                             -ECDSA-AES256-SHA384:ECDH-ECDSA-AES128-SHA256&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               compressed = false&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               connectionTimeout = 20&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf                 defaultGroup = default                                                                                                             -autolb-group&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               disabled = false&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               dropClonedEventsOnQueu                                                                                                             eFull = 5&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               dropEventsOnQueueFull                                                                                                              = -1&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               ecdhCurves = prime256v                                                                                                             1, secp384r1, secp521r1&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               forceTimebasedAutoLB =                                                                                                              false&lt;BR /&gt;
/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf forwardedindex.0.white                                                                                                             list = .*&lt;BR /&gt;
/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf forwardedindex.1.black                                                                                                             list = _.*&lt;BR /&gt;
/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf forwardedindex.filter.                                                                                                             disable = false&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               heartbeatFrequency = 3                                                                                                             0&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf                 indexAndForward = 1&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               maxConnectionsPerIndex                                                                                                             er = 2&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               maxFailuresPerInterval                                                                                                              = 2&lt;BR /&gt;
/opt/splunk/etc/apps/SplunkForwarder/default/outputs.conf maxQueueSize = 500KB&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               readTimeout = 300&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               secsInFailureInterval                                                                                                              = 1&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               sendCookedData = true&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               sslQuietShutdown = fal                                                                                                             se&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               sslVersions = tls1.2&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               tcpSendBufSz = 0&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               useACK = false&lt;BR /&gt;
/opt/splunk/etc/system/default/outputs.conf               writeTimeout = 300&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf                 [tcpout-server://10.19                                                                                                             .1.158:514]&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf                 [tcpout:default-autolb                                                                                                             -group]&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf                 disabled = false&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf                 sendCookedData = false&lt;BR /&gt;
/opt/splunk/etc/system/local/outputs.conf                 server = 10.19.1.158:5                                                                                                             14&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 08:57:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Having-trouble-to-forward-data-to-Kiwi-syslog/m-p/336128#M12559</guid>
      <dc:creator>cemiam</dc:creator>
      <dc:date>2017-10-30T08:57:38Z</dc:date>
    </item>
  </channel>
</rss>

