<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What is the best way to send Mulesoft logs to Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-send-Mulesoft-logs-to-Splunk/m-p/619318#M106787</link>
    <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;
&lt;P&gt;I'm searching about the best way to send Mulesoft logs and events.&lt;BR /&gt;Here on community I found&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-integrate-Mulesoft-with-Splunk-cloud/m-p/526143" target="_self"&gt;What is the best way to integrate Mulesoft with Splunk cloud?&lt;/A&gt;&amp;nbsp;that states, in a nutshell, to follow&amp;nbsp;&lt;A href="https://www.caeliusconsulting.com/blogs/mulesoft-splunk-integration/" target="_self"&gt;this approach.&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is clear enough how to implement it; my doubt is not related so to the procedure, but to another point.&lt;BR /&gt;The above link show, let's say, a direct forwarding from Mulesoft to Splunk Indexer/environment.&amp;nbsp;&lt;BR /&gt;What about if I plan to put a HF between Mulesoft and the indexers?&amp;nbsp;&lt;BR /&gt;I mean: I have to follow the same procedure, simply creating the token on my HF and then, once data arrived from Mulesoft, forward them to Indexer by the usual way? Or there are some change I have to perform?&lt;BR /&gt;&lt;BR /&gt;Note: I supposed, as intermediate host, a HF for the token required generation. I supposed I cannot generate one on a UF. Feel free to correct me if I'm wrong.&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2022 16:34:45 GMT</pubDate>
    <dc:creator>SplunkExplorer</dc:creator>
    <dc:date>2022-11-02T16:34:45Z</dc:date>
    <item>
      <title>What is the best way to send Mulesoft logs to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-send-Mulesoft-logs-to-Splunk/m-p/619318#M106787</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;
&lt;P&gt;I'm searching about the best way to send Mulesoft logs and events.&lt;BR /&gt;Here on community I found&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-integrate-Mulesoft-with-Splunk-cloud/m-p/526143" target="_self"&gt;What is the best way to integrate Mulesoft with Splunk cloud?&lt;/A&gt;&amp;nbsp;that states, in a nutshell, to follow&amp;nbsp;&lt;A href="https://www.caeliusconsulting.com/blogs/mulesoft-splunk-integration/" target="_self"&gt;this approach.&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is clear enough how to implement it; my doubt is not related so to the procedure, but to another point.&lt;BR /&gt;The above link show, let's say, a direct forwarding from Mulesoft to Splunk Indexer/environment.&amp;nbsp;&lt;BR /&gt;What about if I plan to put a HF between Mulesoft and the indexers?&amp;nbsp;&lt;BR /&gt;I mean: I have to follow the same procedure, simply creating the token on my HF and then, once data arrived from Mulesoft, forward them to Indexer by the usual way? Or there are some change I have to perform?&lt;BR /&gt;&lt;BR /&gt;Note: I supposed, as intermediate host, a HF for the token required generation. I supposed I cannot generate one on a UF. Feel free to correct me if I'm wrong.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 16:34:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-send-Mulesoft-logs-to-Splunk/m-p/619318#M106787</guid>
      <dc:creator>SplunkExplorer</dc:creator>
      <dc:date>2022-11-02T16:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to send Mulesoft logs to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-send-Mulesoft-logs-to-Splunk/m-p/619333#M106793</link>
      <description>&lt;P&gt;If you insist on using an intermediate heavy forwarder (they should be avoided when possible) then the procedure is the same except the token is created on the HF rather than on the indexers.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 16:50:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-send-Mulesoft-logs-to-Splunk/m-p/619333#M106793</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-11-02T16:50:11Z</dc:date>
    </item>
  </channel>
</rss>

