<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: spunk cloud- getting data in in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-steps-of-ingesting-data-into-Splunk-cloud/m-p/584383#M102862</link>
    <description>&lt;P&gt;With windows you typically set up a Universal Forwarder on monitored machine(s), define inputs for the event logs you want to pull, point your output to your cloud instance and that's pretty much it.&lt;/P&gt;&lt;P&gt;With the "network/firewall" whatever that means it can be more complicated. I assume that you'll be getting events from those devices by meand of syslog. So you need something to listen for syslog events and write them to splunk. Might be a simple Universal Forwarder (but using raw tcp/udp inputs on UF in production environment is not a best idea), might be SC4S instance, might be rsyslog or whatever you want. There are many different ways to handle syslog.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Feb 2022 20:33:00 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2022-02-09T20:33:00Z</dc:date>
    <item>
      <title>What are the steps of ingesting data into Splunk cloud?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-steps-of-ingesting-data-into-Splunk-cloud/m-p/584355#M102857</link>
      <description>&lt;P&gt;Can someone walk me through the steps of ingesting data into splunk cloud. I have read the documentation but it gets confusing.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 18:34:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-steps-of-ingesting-data-into-Splunk-cloud/m-p/584355#M102857</guid>
      <dc:creator>cyber22</dc:creator>
      <dc:date>2022-02-09T18:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: spunk cloud- getting data in</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-steps-of-ingesting-data-into-Splunk-cloud/m-p/584363#M102860</link>
      <description>&lt;P&gt;Given there is a fair amount of documentation on the topic, it's not reasonable to expect full coverage of it here.&amp;nbsp; Specific questions are more likely to get helpful answers.&lt;/P&gt;&lt;P&gt;There are many ways to get data into Splunk Cloud and which one to use will depend on the data source, your Splunk Cloud "experience",&amp;nbsp; and other factors.&amp;nbsp; Tell us more about what data want to ingest and we should be able to offer some tips on how to do it.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 18:16:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-steps-of-ingesting-data-into-Splunk-cloud/m-p/584363#M102860</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-02-09T18:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: spunk cloud- getting data in</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-steps-of-ingesting-data-into-Splunk-cloud/m-p/584364#M102861</link>
      <description>&lt;P&gt;firewall/network&lt;/P&gt;&lt;P&gt;windows logs&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 18:26:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-steps-of-ingesting-data-into-Splunk-cloud/m-p/584364#M102861</guid>
      <dc:creator>cyber22</dc:creator>
      <dc:date>2022-02-09T18:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: spunk cloud- getting data in</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-steps-of-ingesting-data-into-Splunk-cloud/m-p/584383#M102862</link>
      <description>&lt;P&gt;With windows you typically set up a Universal Forwarder on monitored machine(s), define inputs for the event logs you want to pull, point your output to your cloud instance and that's pretty much it.&lt;/P&gt;&lt;P&gt;With the "network/firewall" whatever that means it can be more complicated. I assume that you'll be getting events from those devices by meand of syslog. So you need something to listen for syslog events and write them to splunk. Might be a simple Universal Forwarder (but using raw tcp/udp inputs on UF in production environment is not a best idea), might be SC4S instance, might be rsyslog or whatever you want. There are many different ways to handle syslog.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Feb 2022 20:33:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-steps-of-ingesting-data-into-Splunk-cloud/m-p/584383#M102862</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-02-09T20:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: What are the steps of ingesting data into Splunk cloud?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-steps-of-ingesting-data-into-Splunk-cloud/m-p/584411#M102869</link>
      <description>&lt;P&gt;Each data source is different, but I noticed you tagged this for Windows so I'll post this guide:&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.2.2112/Admin/WindowsGDI#Overview" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.2.2112/Admin/WindowsGDI#Overview&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Essentially you login to the Splunk Cloud Search Head, download the Universal Forwarder app and you distribute that app to the /opt/splunkforwarder/etc/apps/ directory of the machines you want to send data to the Cloud.&lt;/P&gt;&lt;P&gt;Depending on your needs and network architecture, it could get more complicated, but that is the simple version.&lt;/P&gt;&lt;P&gt;So each Windows Server would need a Splunk UF (Universal Forwarder) and the Spunk Cloud UF app/ta/add-on (TA stands for Technical Add-on) to be able to send and collect data.&lt;/P&gt;&lt;P&gt;Each data source also needs a configuration telling it what data to collect.&lt;BR /&gt;This is often achieved by using a Splunk TA aka add-on on Splunkbase:&lt;BR /&gt;&lt;A href="https://splunkbase.splunk.com/" target="_blank"&gt;https://splunkbase.splunk.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can download the Splunk UF here:&lt;BR /&gt;&lt;A href="https://www.splunk.com/en_us/download/universal-forwarder.html" target="_blank"&gt;https://www.splunk.com/en_us/download/universal-forwarder.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For larger environments, the UF and required addons are usually distributed via a Splunk Deployment Server.&lt;BR /&gt;Also, often data is sent through one or more Forwarders before Cloud to minimize firewall rules, or depending on your network architecture needs.&lt;/P&gt;&lt;P&gt;All data sources need to be able to send data via tcp/9997 to Splunk Cloud.&lt;/P&gt;&lt;P&gt;So the breakdown of steps is:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create an index on Splunk Cloud to receive your data&lt;/LI&gt;&lt;LI&gt;Download the Cloud TA (called Cloud Universal Forwarder) from Splunk Cloud Search Head&lt;/LI&gt;&lt;LI&gt;Install a UF and the Cloud TA onto your data source&lt;OL&gt;&lt;LI&gt;The Cloud TA needs to be untar'd to /opt/splunkforwarder/etc/apps/&lt;/LI&gt;&lt;LI&gt;Or it can be distributed via Splunk Deployment Server&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Install one or more add-ons aka TAs to&amp;nbsp;/opt/splunkforwarder/etc/apps/&lt;/LI&gt;&lt;LI&gt;Configure and enable one or more 'inputs' or data to send by editing the inputs.conf within each TA/add-on&lt;OL&gt;&lt;LI&gt;There is usually a template inputs.conf in the default folder of each add-on.&lt;/LI&gt;&lt;LI&gt;Create a /local folder (same level as /default) in each TA and copy that inputs.conf in there&lt;/LI&gt;&lt;LI&gt;Edit it and enable one or more inputs to send data to Splunk&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;There actually is an 'outputs.conf' but the Splunk Cloud TA/UF handles that to securely send to Splunk Cloud.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 00:29:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-steps-of-ingesting-data-into-Splunk-cloud/m-p/584411#M102869</guid>
      <dc:creator>moliminous</dc:creator>
      <dc:date>2022-02-10T00:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: What are the steps of ingesting data into Splunk cloud?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-steps-of-ingesting-data-into-Splunk-cloud/m-p/590915#M103518</link>
      <description>&lt;P&gt;It totally depends on the log source you are dealing with.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Windows/Linux:&lt;/STRONG&gt; Install UF, add Splunk Cloud Credential File. Edit input.conf file if you want to change the Index.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Firewall Logs:&amp;nbsp;&lt;/STRONG&gt;If you have a Syslog server in place, install a UF on it and redirect the logs from the Syslog folder to it. If you do not have a Syslog server, you can use a Heavy Forwarder configured as a Syslog Receiver.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Cloud-Based:&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;Check for supported apps. Most of them support API based integration, which is easy to do. Each app includes the steps to follow.&lt;/P&gt;&lt;P&gt;Let me know if you have any specific devices in question. I am no expert, but will definitely try to help you out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 18:25:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-steps-of-ingesting-data-into-Splunk-cloud/m-p/590915#M103518</guid>
      <dc:creator>shubham92</dc:creator>
      <dc:date>2022-03-25T18:25:19Z</dc:date>
    </item>
  </channel>
</rss>

