<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: automatic lookup on splunkforwarder in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/automatic-lookup-on-splunkforwarder/m-p/258193#M9812</link>
    <description>&lt;P&gt;The Universal Forwarder only forwards.  To do anything else, you must install a Heavy Forwarder.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Nov 2015 17:54:20 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2015-11-30T17:54:20Z</dc:date>
    <item>
      <title>automatic lookup on splunkforwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/automatic-lookup-on-splunkforwarder/m-p/258192#M9811</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;is it possible, to implement automatic lookups on a splunk forwarder?&lt;BR /&gt;
The reason for this request is, that i´ve already installed the splunk forwarder on a linux-based vpn-server.&lt;BR /&gt;
The forwarder already monitors the log file of the vpn-process (racoon) and forward it to our central splunk indexer.&lt;BR /&gt;
But there is a need, to add data to the logfile, befor it is send to the indexer, because the data which has to be added are only available at run-time on the linux system itself and depends on the information of each log line. Therefor i´ve no chance with an lookup at the central splunk indexer.&lt;/P&gt;

&lt;P&gt;regards&lt;BR /&gt;
Michael&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 15:10:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/automatic-lookup-on-splunkforwarder/m-p/258192#M9811</guid>
      <dc:creator>mbrussk</dc:creator>
      <dc:date>2015-11-30T15:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: automatic lookup on splunkforwarder</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/automatic-lookup-on-splunkforwarder/m-p/258193#M9812</link>
      <description>&lt;P&gt;The Universal Forwarder only forwards.  To do anything else, you must install a Heavy Forwarder.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2015 17:54:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/automatic-lookup-on-splunkforwarder/m-p/258193#M9812</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-11-30T17:54:20Z</dc:date>
    </item>
  </channel>
</rss>

