<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query to forward logs from UF to Syslog-ng using either BSD/IETF syslog format in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-logs-from-UF-to-Syslog-ng-using-either/m-p/622374#M107143</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Yes it's possible, at least on HF side, but why you don't send all to syslog-ng and then read those by UF from syslog-ng server? That is much better approach than use splunk to deliver syslog.&lt;/P&gt;&lt;P&gt;If you still want to do it by splunk, there are lot of examples on community and docs.splunk.com e..g&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Forwarding-data-from-Heavy-forwarder-to-syslog-server/m-p/473916" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Forwarding-data-from-Heavy-forwarder-to-syslog-server/m-p/473916&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Tue, 29 Nov 2022 09:42:02 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-11-29T09:42:02Z</dc:date>
    <item>
      <title>Is it possible to forward logs from UF to Syslog-ng using either BSD/IETF syslog format?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-logs-from-UF-to-Syslog-ng-using-either/m-p/622359#M107142</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I was posed a query from my customer. Is it possible to forward syslog from UF to Syslog-ng using the BSD/IETF syslog format? If so, how would one go about implementing it?&lt;/P&gt;
&lt;P&gt;Thank you in advance for any information provided.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Mikhael&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 14:03:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-logs-from-UF-to-Syslog-ng-using-either/m-p/622359#M107142</guid>
      <dc:creator>mohdmikhael</dc:creator>
      <dc:date>2022-11-29T14:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: Query to forward logs from UF to Syslog-ng using either BSD/IETF syslog format</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-logs-from-UF-to-Syslog-ng-using-either/m-p/622374#M107143</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Yes it's possible, at least on HF side, but why you don't send all to syslog-ng and then read those by UF from syslog-ng server? That is much better approach than use splunk to deliver syslog.&lt;/P&gt;&lt;P&gt;If you still want to do it by splunk, there are lot of examples on community and docs.splunk.com e..g&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Forwarding-data-from-Heavy-forwarder-to-syslog-server/m-p/473916" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Forwarding-data-from-Heavy-forwarder-to-syslog-server/m-p/473916&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 09:42:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-logs-from-UF-to-Syslog-ng-using-either/m-p/622374#M107143</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-11-29T09:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: Query to forward logs from UF to Syslog-ng using either BSD/IETF syslog format</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-logs-from-UF-to-Syslog-ng-using-either/m-p/622381#M107145</link>
      <description>&lt;P&gt;The question was about UF. And on UF it's not possible. Quoting from outputs.conf spec:&lt;/P&gt;&lt;PRE&gt;# The syslog output processor is not available for universal or light
# forwarders.&lt;/PRE&gt;&lt;P&gt;Anyway, I suppose it's a case of replacing one solution with another or implementing two different solutions for two different purposes (like Splunk for security and some syslog collector for ops). I'd probably also suggest doing the syslog part first and pass the events to the Splunk layer (either by saving to files and ingesting the files with UF or by pushing them directly to HEC from the syslog server, bypassing UF completely).&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 10:43:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-logs-from-UF-to-Syslog-ng-using-either/m-p/622381#M107145</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-11-29T10:43:37Z</dc:date>
    </item>
  </channel>
</rss>

