<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sending Windows Eventlogs from splunk forwarder via a heavyforwarder to indexers in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576409#M25063</link>
    <description>&lt;P&gt;Splunk forwarder: outputs.conf&lt;/P&gt;&lt;P&gt;[tcpout]&lt;BR /&gt;defaultGroup=xxxhf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[tcpout:xxxhf]&lt;BR /&gt;autoLBFrequency=40&lt;BR /&gt;server=x.x.x.x:xxxx&lt;BR /&gt;useACK=true&lt;BR /&gt;indexandforward=false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Heavy forwarder : inputs.conf&lt;/P&gt;&lt;P&gt;[tcp://xxxxx]&lt;/P&gt;&lt;P&gt;sourcetype=WinEventLog&lt;BR /&gt;index=xxxxx&lt;BR /&gt;disabled = 0&lt;/P&gt;&lt;P&gt;inputs on indexers :&amp;nbsp;&lt;/P&gt;&lt;P&gt;[splunktcp:xxxx]&lt;/P&gt;</description>
    <pubDate>Fri, 26 Nov 2021 10:29:50 GMT</pubDate>
    <dc:creator>KulvinderSingh</dc:creator>
    <dc:date>2021-11-26T10:29:50Z</dc:date>
    <item>
      <title>Sending Windows Eventlogs from splunk forwarder via a heavyforwarder to indexers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576407#M25061</link>
      <description>&lt;P&gt;hi All,&lt;/P&gt;&lt;P&gt;I need to send windows event logs from Splunkforwarder to Indexers via a heavyforwarder.&lt;/P&gt;&lt;P&gt;I have done some configuration but it seems like something is incorrect as I am getting cooked data in splunk instead of logs.&lt;/P&gt;&lt;P&gt;All the help is appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 10:03:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576407#M25061</guid>
      <dc:creator>KulvinderSingh</dc:creator>
      <dc:date>2021-11-26T10:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: Sending Windows Eventlogs from splunk forwarder via a heavyforwarder to indexers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576408#M25062</link>
      <description>&lt;P&gt;We don't know your config but I'd dare to guess that you're sending to tcp: input instead of splunktcp: one.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 10:18:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576408#M25062</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-26T10:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: Sending Windows Eventlogs from splunk forwarder via a heavyforwarder to indexers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576409#M25063</link>
      <description>&lt;P&gt;Splunk forwarder: outputs.conf&lt;/P&gt;&lt;P&gt;[tcpout]&lt;BR /&gt;defaultGroup=xxxhf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[tcpout:xxxhf]&lt;BR /&gt;autoLBFrequency=40&lt;BR /&gt;server=x.x.x.x:xxxx&lt;BR /&gt;useACK=true&lt;BR /&gt;indexandforward=false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Heavy forwarder : inputs.conf&lt;/P&gt;&lt;P&gt;[tcp://xxxxx]&lt;/P&gt;&lt;P&gt;sourcetype=WinEventLog&lt;BR /&gt;index=xxxxx&lt;BR /&gt;disabled = 0&lt;/P&gt;&lt;P&gt;inputs on indexers :&amp;nbsp;&lt;/P&gt;&lt;P&gt;[splunktcp:xxxx]&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 10:29:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576409#M25063</guid>
      <dc:creator>KulvinderSingh</dc:creator>
      <dc:date>2021-11-26T10:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: Sending Windows Eventlogs from splunk forwarder via a heavyforwarder to indexers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576410#M25064</link>
      <description>&lt;P&gt;You have tcp: on HF, as I said. You need to send from UF to HF on splunktcp input.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 10:38:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576410#M25064</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-26T10:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Sending Windows Eventlogs from splunk forwarder via a heavyforwarder to indexers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576411#M25065</link>
      <description>&lt;P&gt;Okay got it, I have changed it to splunktcp on forwarder and even I can read the logs in splunk SH but still sourcetype of logs is coming in as xmlWinEventlog instead of WinEventLog. I have the SpluK_TA_Windows on indexers as well as on HF and SF. But this I think is close to resolving the issue if i can just sort this small thing.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 10:45:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576411#M25065</guid>
      <dc:creator>KulvinderSingh</dc:creator>
      <dc:date>2021-11-26T10:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Sending Windows Eventlogs from splunk forwarder via a heavyforwarder to indexers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576430#M25066</link>
      <description>&lt;P&gt;You define the sourcetype and whether you want the events rendered as xml or in "old format" in inputs.conf&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 13:47:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576430#M25066</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-26T13:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Sending Windows Eventlogs from splunk forwarder via a heavyforwarder to indexers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576437#M25067</link>
      <description>&lt;P&gt;so you mean to say in splunkforwarder inputs.conf i should set renderXML = false and that should fix it or will i have to do that everywhere like on SF,HF,IX all 3 places? sorry doing this for the first time. Getting windows logs is easiest of all but the way i am trying its looking very difficult.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 14:20:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576437#M25067</guid>
      <dc:creator>KulvinderSingh</dc:creator>
      <dc:date>2021-11-26T14:20:13Z</dc:date>
    </item>
    <item>
      <title>Re: Sending Windows Eventlogs from splunk forwarder via a heavyforwarder to indexers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576442#M25068</link>
      <description>&lt;P&gt;OK. Baby steps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In the inputs.conf file on the UF you set how you want the events from the EventLog pulled - as XML or not.&lt;/P&gt;&lt;P&gt;Then you send it to HF, which sends data to indexer(s).&lt;/P&gt;&lt;P&gt;The app installed on the SH-s are responsible for search-time extractions.&lt;/P&gt;&lt;P&gt;I don't remember if the TA for windows does any index-time data modifications - you have to check the docs. If it does, you'd also need it on the HF. But I don't recall installing it there.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2021 15:28:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Sending-Windows-Eventlogs-from-splunk-forwarder-via-a/m-p/576442#M25068</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-26T15:28:38Z</dc:date>
    </item>
  </channel>
</rss>

