<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: forwarding syslog data via UDP to 3rd party server.  splunk docs instructions not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/forwarding-syslog-data-via-UDP-to-3rd-party-server-splunk-docs/m-p/53523#M10331</link>
    <description>&lt;P&gt;Good day&lt;/P&gt;

&lt;P&gt;I have a question.&lt;/P&gt;

&lt;P&gt;Where i can find and edit this? &lt;/P&gt;

&lt;P&gt;1.)tranforms.conf&lt;BR /&gt;
2.)props.conf&lt;BR /&gt;
3.)outputs.conf&lt;/P&gt;

&lt;P&gt;i am using windows and have a splunk instance version version 4.3.4, build 136012&lt;/P&gt;

&lt;P&gt;thanks&lt;BR /&gt;
Cris&lt;/P&gt;</description>
    <pubDate>Thu, 11 Oct 2012 10:14:55 GMT</pubDate>
    <dc:creator>christantoy</dc:creator>
    <dc:date>2012-10-11T10:14:55Z</dc:date>
    <item>
      <title>forwarding syslog data via UDP to 3rd party server.  splunk docs instructions not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarding-syslog-data-via-UDP-to-3rd-party-server-splunk-docs/m-p/53519#M10327</link>
      <description>&lt;P&gt;I tried the following and it did not work - &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Forwarddatatothird-partysystemsd" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Forwarddatatothird-partysystemsd&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I have since been able to forward ALL data via UDP to the 3rd party system but have not been able to filter specific events.  First I tried the following which did not work - &lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;P&gt;[host::10.10.10.*]&lt;BR /&gt;
TRANSFORMS-bna = send_to_syslog&lt;/P&gt;

&lt;P&gt;tranforms.conf&lt;/P&gt;

&lt;P&gt;[send_to_syslog]&lt;BR /&gt;
DEST_KEY = _SYSLOG_ROUTING&lt;BR /&gt;
REGEX=SYSMGR-6-SUBPROC_SUCCESS_EXIT&lt;BR /&gt;
FORMAT = my_syslog_group&lt;/P&gt;

&lt;P&gt;(note that I tried this without the REGEX as well)&lt;/P&gt;

&lt;P&gt;outputs.conf&lt;/P&gt;

&lt;P&gt;[syslog:my_syslog_group]&lt;BR /&gt;
server = 10.10.10.10:514&lt;/P&gt;

&lt;P&gt;I verified that the 3rd party system is receiving syslogs via UDP correctly through another mechanism.  I also verified that the events I want are coming in from the proper IP with the proper string.  If I just put the following in my outputs.conf I get ALL syslog events via UDP to the server but filtering is not working even with the props and transforms in place - &lt;/P&gt;

&lt;P&gt;[syslog]&lt;BR /&gt;
defaultGroup = my_syslog_group&lt;/P&gt;

&lt;P&gt;[syslog:my_syslog_group]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
server = 10.10.10.10:514&lt;/P&gt;

&lt;P&gt;Any ideas?  This is from an indexer running 4.1.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:19:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarding-syslog-data-via-UDP-to-3rd-party-server-splunk-docs/m-p/53519#M10327</guid>
      <dc:creator>jfraiberg</dc:creator>
      <dc:date>2020-09-28T10:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding syslog data via UDP to 3rd party server.  splunk docs instructions not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarding-syslog-data-via-UDP-to-3rd-party-server-splunk-docs/m-p/53520#M10328</link>
      <description>&lt;P&gt;I am having the exact same issue.  Anyone ever resolve this?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2012 17:13:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarding-syslog-data-via-UDP-to-3rd-party-server-splunk-docs/m-p/53520#M10328</guid>
      <dc:creator>chadfermanxto</dc:creator>
      <dc:date>2012-08-06T17:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding syslog data via UDP to 3rd party server.  splunk docs instructions not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarding-syslog-data-via-UDP-to-3rd-party-server-splunk-docs/m-p/53521#M10329</link>
      <description>&lt;P&gt;I opened a ticket and it ended up being a bug.  I was forced to upgrade to the latest version, once I did that the configs worked.  I could not get it to work by host however, only by source with regex.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2012 17:19:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarding-syslog-data-via-UDP-to-3rd-party-server-splunk-docs/m-p/53521#M10329</guid>
      <dc:creator>jfraiberg</dc:creator>
      <dc:date>2012-08-06T17:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding syslog data via UDP to 3rd party server.  splunk docs instructions not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarding-syslog-data-via-UDP-to-3rd-party-server-splunk-docs/m-p/53522#M10330</link>
      <description>&lt;P&gt;what version fixed the problem 4.3.4 or 4.3.3 ?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2012 16:21:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarding-syslog-data-via-UDP-to-3rd-party-server-splunk-docs/m-p/53522#M10330</guid>
      <dc:creator>herterich</dc:creator>
      <dc:date>2012-10-09T16:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding syslog data via UDP to 3rd party server.  splunk docs instructions not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarding-syslog-data-via-UDP-to-3rd-party-server-splunk-docs/m-p/53523#M10331</link>
      <description>&lt;P&gt;Good day&lt;/P&gt;

&lt;P&gt;I have a question.&lt;/P&gt;

&lt;P&gt;Where i can find and edit this? &lt;/P&gt;

&lt;P&gt;1.)tranforms.conf&lt;BR /&gt;
2.)props.conf&lt;BR /&gt;
3.)outputs.conf&lt;/P&gt;

&lt;P&gt;i am using windows and have a splunk instance version version 4.3.4, build 136012&lt;/P&gt;

&lt;P&gt;thanks&lt;BR /&gt;
Cris&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2012 10:14:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarding-syslog-data-via-UDP-to-3rd-party-server-splunk-docs/m-p/53523#M10331</guid>
      <dc:creator>christantoy</dc:creator>
      <dc:date>2012-10-11T10:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: forwarding syslog data via UDP to 3rd party server.  splunk docs instructions not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarding-syslog-data-via-UDP-to-3rd-party-server-splunk-docs/m-p/53524#M10332</link>
      <description>&lt;P&gt;3.3 fixed it&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2012 13:51:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarding-syslog-data-via-UDP-to-3rd-party-server-splunk-docs/m-p/53524#M10332</guid>
      <dc:creator>jfraiberg</dc:creator>
      <dc:date>2012-10-11T13:51:44Z</dc:date>
    </item>
  </channel>
</rss>

