<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk indexer is not sending to syslog - please help in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56714#M11042</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;all files edited in SPLUNK_HOME/etc/system/local/&lt;/P&gt;

&lt;P&gt;outputs.conf&lt;/P&gt;

&lt;P&gt;[syslog] &lt;/P&gt;

&lt;P&gt;defaultGroup = mysyslog &lt;/P&gt;

&lt;P&gt;[syslog:mysyslog] &lt;/P&gt;

&lt;P&gt;server = 192.168.9.151:514&lt;/P&gt;

&lt;P&gt;type = udp&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;P&gt;[host::*]&lt;/P&gt;

&lt;P&gt;TRANSFORMS-routing = send_to_syslog&lt;/P&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;P&gt;[send_to_syslog]&lt;/P&gt;

&lt;P&gt;REGEX = .&lt;/P&gt;

&lt;P&gt;DEST_KEY = _SYSLOG_ROUTING&lt;/P&gt;

&lt;P&gt;FORMAT = mysyslog&lt;/P&gt;

&lt;P&gt;output of &lt;/P&gt;

&lt;P&gt;/opt/splunk/bin/splunk cmd btool outputs list --debug&lt;BR /&gt;
system     [syslog]&lt;BR /&gt;
system     defaultGroup = mysyslog&lt;BR /&gt;
system     [syslog:mysyslog]&lt;BR /&gt;
system     server = 192.168.9.151:514&lt;BR /&gt;
system     type = udp&lt;BR /&gt;
system     [tcpout]&lt;BR /&gt;
system     autoLB = true&lt;BR /&gt;
system     autoLBFrequency = 30&lt;BR /&gt;
system     blockOnCloning = true&lt;BR /&gt;
system     compressed = false&lt;BR /&gt;
system     connectionTimeout = 20&lt;BR /&gt;
system     disabled = false&lt;BR /&gt;
system     dropClonedEventsOnQueueFull = 5&lt;BR /&gt;
system     dropEventsOnQueueFull = -1&lt;BR /&gt;
system     forwardedindex.0.whitelist = .*&lt;BR /&gt;
system     forwardedindex.1.blacklist = _.*&lt;BR /&gt;
system     forwardedindex.2.whitelist = _audit&lt;BR /&gt;
system     forwardedindex.filter.disable = false&lt;BR /&gt;
system     heartbeatFrequency = 30&lt;BR /&gt;
system     indexAndForward = false&lt;BR /&gt;
system     maxConnectionsPerIndexer = 2&lt;BR /&gt;
system     maxFailuresPerInterval = 2&lt;BR /&gt;
system     maxQueueSize = 500KB&lt;BR /&gt;
system     readTimeout = 300&lt;BR /&gt;
system     secsInFailureInterval = 1&lt;BR /&gt;
system     sendCookedData = true&lt;BR /&gt;
system     useACK = false&lt;BR /&gt;
system     writeTimeout = 300&lt;/P&gt;

&lt;P&gt;output of&lt;/P&gt;

&lt;P&gt;/opt/splunk/bin/splunk cmd btool props list --debug|grep syslog&lt;BR /&gt;
system     [anaconda_syslog]&lt;BR /&gt;
system     REPORT-syslog = syslog-extractions&lt;BR /&gt;
system     [cisco_syslog]&lt;BR /&gt;
system     REPORT-syslog = syslog-extractions&lt;BR /&gt;
system     TRANSFORMS = syslog-host&lt;BR /&gt;
system     [delayedrule::syslog]&lt;BR /&gt;
system     sourcetype = syslog&lt;BR /&gt;
system     TRANSFORMS-routing = send_to_syslog&lt;BR /&gt;
system     [linux_messages_syslog]&lt;BR /&gt;
system     REPORT-syslog = syslog-extractions&lt;BR /&gt;
system     TRANSFORMS = syslog-host&lt;BR /&gt;
system     REPORT-syslog = syslog-extractions&lt;BR /&gt;
system     [postfix_syslog]&lt;BR /&gt;
system     REPORT-syslog = syslog-extractions&lt;BR /&gt;
system     TRANSFORMS-host = syslog-host&lt;BR /&gt;
system     [rule::postfix_syslog]&lt;BR /&gt;
system     sourcetype = postfix_syslog&lt;BR /&gt;
system     [rule::sendmail_syslog]&lt;BR /&gt;
system     sourcetype = sendmail_syslog&lt;BR /&gt;
system     [sendmail_syslog]&lt;BR /&gt;
system     REPORT-syslog = sendmail-extractions&lt;BR /&gt;
system     TRANSFORMS = syslog-host&lt;BR /&gt;
system     sourcetype = syslog&lt;BR /&gt;
system     sourcetype = syslog&lt;BR /&gt;
system     sourcetype = syslog&lt;BR /&gt;
system     [source::.../syslog(.\d+)?]&lt;BR /&gt;
system     sourcetype = syslog&lt;BR /&gt;
system     [source::.../var/log/anaconda.syslog(.\d+)?]&lt;BR /&gt;
system     sourcetype = anaconda_syslog&lt;BR /&gt;
system     [syslog]&lt;BR /&gt;
system     REPORT-syslog = syslog-extractions&lt;BR /&gt;
system     TRANSFORMS = syslog-host&lt;BR /&gt;
system     [windows_snare_syslog]&lt;BR /&gt;
system     REPORT-syslog = syslog-extractions&lt;BR /&gt;
system     TRANSFORMS = syslog-host&lt;/P&gt;

&lt;P&gt;output of&lt;BR /&gt;
/opt/splunk/bin/splunk cmd btool transforms list --debug&lt;BR /&gt;
system     [send_to_syslog]&lt;BR /&gt;
system     CAN_OPTIMIZE = True&lt;BR /&gt;
system     CLEAN_KEYS = True&lt;BR /&gt;
system     DEFAULT_VALUE =&lt;BR /&gt;
system     DEST_KEY = _SYSLOG_ROUTING&lt;BR /&gt;
system     FORMAT = mysyslog&lt;BR /&gt;
system     KEEP_EMPTY_VALS = False&lt;BR /&gt;
system     LOOKAHEAD = 4096&lt;BR /&gt;
system     MV_ADD = False&lt;BR /&gt;
system     REGEX = .&lt;BR /&gt;
system     SOURCE_KEY = _raw&lt;BR /&gt;
system     WRITE_META = False&lt;/P&gt;

&lt;P&gt;I can see that in props there is delayedrule and not host::* - what does it mean?&lt;BR /&gt;
Splunk of course restarted. I'm feeding indexer with UF (windows) and syslog generator (UDP:514 - source syslog) - sill no effects &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Alex&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 10:21:13 GMT</pubDate>
    <dc:creator>awalesa</dc:creator>
    <dc:date>2020-09-28T10:21:13Z</dc:date>
    <item>
      <title>Splunk indexer is not sending to syslog - please help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56712#M11040</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I've tried everything. I have read all the answers and docs. A cannot force splunk indexer to forward all events to syslog server. I even tried to look at tcpdump output and here is no trace of communication on desired port.&lt;/P&gt;

&lt;P&gt;Config s simple - UniversalForwarder (Windows Events) -&amp;gt; Splunk Indexer (Linux) -&amp;gt; Syslog (Linux). UF to SI works, SI to Syslog not. tecpdump on SI is not showing any outbound communication to syslog. &lt;/P&gt;

&lt;P&gt;outputs.conf from SI - 192.168.9.22 is IP of Syslog&lt;/P&gt;

&lt;P&gt;[syslog]&lt;/P&gt;

&lt;P&gt;defaultGroup = mysyslog&lt;/P&gt;

&lt;P&gt;[syslog:mysyslog]&lt;/P&gt;

&lt;P&gt;server = 192.168.9.22:514&lt;/P&gt;

&lt;P&gt;type = udp&lt;/P&gt;

&lt;P&gt;I don't want fo filter anything so I'm not using props.conf and transforms.conf - but with them the situation is the same - no communication between SI and Syslog. &lt;/P&gt;

&lt;P&gt;Maybe I have some component disabled or something? I have tried this config on both linux and Windows (all version 4.3) and no luck.&lt;/P&gt;

&lt;P&gt;Anyone has working config files to share? Any ideas?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Alex&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2012 09:46:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56712#M11040</guid>
      <dc:creator>awalesa</dc:creator>
      <dc:date>2012-01-24T09:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexer is not sending to syslog - please help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56713#M11041</link>
      <description>&lt;P&gt;A few things to check.&lt;BR /&gt;
Have you restarted the Splunk indexer? this is required for it to read in the updated config.&lt;/P&gt;

&lt;P&gt;Secondly, have you defined what traffic you want to send? you will need to specify the data even if its everything, e.g. define it for the host field of the UF. Or use wildcards with regex to specify all.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/admin/propsconf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/admin/propsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The need to define the traffic is explained here; (I have pasted a snippet below)&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/admin/Outputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/admin/Outputsconf&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#---- Routing Data to Syslog Server -----
# To route data to syslog server:
# 1) Decide which events to route to which servers.
# 2) Edit the props.conf, transforms.conf, and outputs.conf files on the forwarders.

# Edit $SPLUNK_HOME/etc/system/local/props.conf and set a TRANSFORMS-routing attribute as shown here:

 [&amp;lt;spec&amp;gt;]
 TRANSFORMS-routing=&amp;lt;unique_stanza_name&amp;gt;

* &amp;lt;spec&amp;gt; can be: 
  * &amp;lt;sourcetype&amp;gt;, the source type of an event 
  * host::&amp;lt;host&amp;gt;, where &amp;lt;host&amp;gt; is the host for an event 
  * source::&amp;lt;source&amp;gt;, where &amp;lt;source&amp;gt; is the source for an event 

* Use the &amp;lt;unique_stanza_name&amp;gt; when creating your entry in transforms.conf.

# Edit $SPLUNK_HOME/etc/system/local/transforms.conf and set rules to match your props.conf stanza: 

  [&amp;lt;unique_stanza_name&amp;gt;]
  REGEX=&amp;lt;your_regex&amp;gt;
  DEST_KEY=_SYSLOG_ROUTING
  FORMAT=&amp;lt;unique_group_name&amp;gt;

* &amp;lt;unique_stanza_name&amp;gt; must match the name you created in props.conf. 
* Enter the regex rules in &amp;lt;your_regex&amp;gt; to determine which events get conditionally routed. 
* DEST_KEY should be set to _SYSLOG_ROUTING to send events via SYSLOG.
* Set FORMAT to &amp;lt;unique_group_name&amp;gt;. This should match the syslog group name you create in outputs.conf.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Finally. If you have defined traffic then run this command and what is the output;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;./splunk cmd btool outputs list --debug
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will list all the outputs.conf detail it has read in, debug forces it to pre-pend each line with the App name that the config has taken effect from.&lt;BR /&gt;
Presumably you are editing outputs.conf in &lt;CODE&gt;SPLUNK_HOME/etc/system/local/&lt;/CODE&gt;?&lt;/P&gt;

&lt;P&gt;EDIT:&lt;BR /&gt;
Ok, so what source does your incoming syslog data (incoming to the indexer) have? E.g. on my system its just syslog-data.&lt;BR /&gt;
In which case, why don't you try applying the props to &lt;A href="https://community.splunk.com/or%20whatever%20the%20source%20is"&gt;source::syslog-data&lt;/A&gt; and see how that performs? Having a search around I have seen a few others had issue using host.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2012 11:43:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56713#M11041</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-01-24T11:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexer is not sending to syslog - please help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56714#M11042</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;all files edited in SPLUNK_HOME/etc/system/local/&lt;/P&gt;

&lt;P&gt;outputs.conf&lt;/P&gt;

&lt;P&gt;[syslog] &lt;/P&gt;

&lt;P&gt;defaultGroup = mysyslog &lt;/P&gt;

&lt;P&gt;[syslog:mysyslog] &lt;/P&gt;

&lt;P&gt;server = 192.168.9.151:514&lt;/P&gt;

&lt;P&gt;type = udp&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;P&gt;[host::*]&lt;/P&gt;

&lt;P&gt;TRANSFORMS-routing = send_to_syslog&lt;/P&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;P&gt;[send_to_syslog]&lt;/P&gt;

&lt;P&gt;REGEX = .&lt;/P&gt;

&lt;P&gt;DEST_KEY = _SYSLOG_ROUTING&lt;/P&gt;

&lt;P&gt;FORMAT = mysyslog&lt;/P&gt;

&lt;P&gt;output of &lt;/P&gt;

&lt;P&gt;/opt/splunk/bin/splunk cmd btool outputs list --debug&lt;BR /&gt;
system     [syslog]&lt;BR /&gt;
system     defaultGroup = mysyslog&lt;BR /&gt;
system     [syslog:mysyslog]&lt;BR /&gt;
system     server = 192.168.9.151:514&lt;BR /&gt;
system     type = udp&lt;BR /&gt;
system     [tcpout]&lt;BR /&gt;
system     autoLB = true&lt;BR /&gt;
system     autoLBFrequency = 30&lt;BR /&gt;
system     blockOnCloning = true&lt;BR /&gt;
system     compressed = false&lt;BR /&gt;
system     connectionTimeout = 20&lt;BR /&gt;
system     disabled = false&lt;BR /&gt;
system     dropClonedEventsOnQueueFull = 5&lt;BR /&gt;
system     dropEventsOnQueueFull = -1&lt;BR /&gt;
system     forwardedindex.0.whitelist = .*&lt;BR /&gt;
system     forwardedindex.1.blacklist = _.*&lt;BR /&gt;
system     forwardedindex.2.whitelist = _audit&lt;BR /&gt;
system     forwardedindex.filter.disable = false&lt;BR /&gt;
system     heartbeatFrequency = 30&lt;BR /&gt;
system     indexAndForward = false&lt;BR /&gt;
system     maxConnectionsPerIndexer = 2&lt;BR /&gt;
system     maxFailuresPerInterval = 2&lt;BR /&gt;
system     maxQueueSize = 500KB&lt;BR /&gt;
system     readTimeout = 300&lt;BR /&gt;
system     secsInFailureInterval = 1&lt;BR /&gt;
system     sendCookedData = true&lt;BR /&gt;
system     useACK = false&lt;BR /&gt;
system     writeTimeout = 300&lt;/P&gt;

&lt;P&gt;output of&lt;/P&gt;

&lt;P&gt;/opt/splunk/bin/splunk cmd btool props list --debug|grep syslog&lt;BR /&gt;
system     [anaconda_syslog]&lt;BR /&gt;
system     REPORT-syslog = syslog-extractions&lt;BR /&gt;
system     [cisco_syslog]&lt;BR /&gt;
system     REPORT-syslog = syslog-extractions&lt;BR /&gt;
system     TRANSFORMS = syslog-host&lt;BR /&gt;
system     [delayedrule::syslog]&lt;BR /&gt;
system     sourcetype = syslog&lt;BR /&gt;
system     TRANSFORMS-routing = send_to_syslog&lt;BR /&gt;
system     [linux_messages_syslog]&lt;BR /&gt;
system     REPORT-syslog = syslog-extractions&lt;BR /&gt;
system     TRANSFORMS = syslog-host&lt;BR /&gt;
system     REPORT-syslog = syslog-extractions&lt;BR /&gt;
system     [postfix_syslog]&lt;BR /&gt;
system     REPORT-syslog = syslog-extractions&lt;BR /&gt;
system     TRANSFORMS-host = syslog-host&lt;BR /&gt;
system     [rule::postfix_syslog]&lt;BR /&gt;
system     sourcetype = postfix_syslog&lt;BR /&gt;
system     [rule::sendmail_syslog]&lt;BR /&gt;
system     sourcetype = sendmail_syslog&lt;BR /&gt;
system     [sendmail_syslog]&lt;BR /&gt;
system     REPORT-syslog = sendmail-extractions&lt;BR /&gt;
system     TRANSFORMS = syslog-host&lt;BR /&gt;
system     sourcetype = syslog&lt;BR /&gt;
system     sourcetype = syslog&lt;BR /&gt;
system     sourcetype = syslog&lt;BR /&gt;
system     [source::.../syslog(.\d+)?]&lt;BR /&gt;
system     sourcetype = syslog&lt;BR /&gt;
system     [source::.../var/log/anaconda.syslog(.\d+)?]&lt;BR /&gt;
system     sourcetype = anaconda_syslog&lt;BR /&gt;
system     [syslog]&lt;BR /&gt;
system     REPORT-syslog = syslog-extractions&lt;BR /&gt;
system     TRANSFORMS = syslog-host&lt;BR /&gt;
system     [windows_snare_syslog]&lt;BR /&gt;
system     REPORT-syslog = syslog-extractions&lt;BR /&gt;
system     TRANSFORMS = syslog-host&lt;/P&gt;

&lt;P&gt;output of&lt;BR /&gt;
/opt/splunk/bin/splunk cmd btool transforms list --debug&lt;BR /&gt;
system     [send_to_syslog]&lt;BR /&gt;
system     CAN_OPTIMIZE = True&lt;BR /&gt;
system     CLEAN_KEYS = True&lt;BR /&gt;
system     DEFAULT_VALUE =&lt;BR /&gt;
system     DEST_KEY = _SYSLOG_ROUTING&lt;BR /&gt;
system     FORMAT = mysyslog&lt;BR /&gt;
system     KEEP_EMPTY_VALS = False&lt;BR /&gt;
system     LOOKAHEAD = 4096&lt;BR /&gt;
system     MV_ADD = False&lt;BR /&gt;
system     REGEX = .&lt;BR /&gt;
system     SOURCE_KEY = _raw&lt;BR /&gt;
system     WRITE_META = False&lt;/P&gt;

&lt;P&gt;I can see that in props there is delayedrule and not host::* - what does it mean?&lt;BR /&gt;
Splunk of course restarted. I'm feeding indexer with UF (windows) and syslog generator (UDP:514 - source syslog) - sill no effects &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Alex&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:21:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56714#M11042</guid>
      <dc:creator>awalesa</dc:creator>
      <dc:date>2020-09-28T10:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexer is not sending to syslog - please help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56715#M11043</link>
      <description>&lt;P&gt;I'll update my answer above, have a looksie&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2012 13:28:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56715#M11043</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-01-24T13:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexer is not sending to syslog - please help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56716#M11044</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have changed props as you suggested - sill no communication - it's look like splunk doesn't even try to send anything to syslog. Just to be sure I have tried to forward events with syslog-ng - with success. For sure there is something wrong with my splunk...&lt;/P&gt;

&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2012 14:32:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56716#M11044</guid>
      <dc:creator>awalesa</dc:creator>
      <dc:date>2012-01-24T14:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexer is not sending to syslog - please help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56717#M11045</link>
      <description>&lt;P&gt;You mention "no communication". Do you have a firewall, or similar software that is blocking/dropping network packets? &lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2012 17:04:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56717#M11045</guid>
      <dc:creator>wcolgate_splunk</dc:creator>
      <dc:date>2012-01-24T17:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexer is not sending to syslog - please help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56718#M11046</link>
      <description>&lt;P&gt;Hi, nothing like that - both servers are on LAN. I can succesfully forward events with syslog-ng between both (disabling splunk for that time). When I try to do the same with splunk nothing happens. When I run tcpdump on indexer (which should send events to syslog) also nothing - even one packet &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Alex&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2012 17:10:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56718#M11046</guid>
      <dc:creator>awalesa</dc:creator>
      <dc:date>2012-01-24T17:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexer is not sending to syslog - please help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56719#M11047</link>
      <description>&lt;P&gt;Is there any debug log or debug switch to see how the routing goes? I just cannot understand why splunk is not forwarding events to syslog...&lt;/P&gt;

&lt;P&gt;ALex&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2012 21:25:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56719#M11047</guid>
      <dc:creator>awalesa</dc:creator>
      <dc:date>2012-01-24T21:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexer is not sending to syslog - please help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56720#M11048</link>
      <description>&lt;P&gt;In the free license the syslog forward feature is disabled - that's why I cannot force splunk to talk to syslog &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2012 10:42:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56720#M11048</guid>
      <dc:creator>awalesa</dc:creator>
      <dc:date>2012-01-25T10:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexer is not sending to syslog - please help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56721#M11049</link>
      <description>&lt;P&gt;Hah! You learn something new every day. Ok, as an aside why did you want to forward onto syslog in the first place?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2012 10:44:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56721#M11049</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-01-25T10:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexer is not sending to syslog - please help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56722#M11050</link>
      <description>&lt;P&gt;Hi, I like the format of windows events send directly form UF to indexer and the UF cannot send to syslog &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; I tried to use snare as syslog client to syslog ant then to splunk but the output at the end is messed (internatiolan letters, one single line etc)&lt;/P&gt;

&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2012 10:49:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56722#M11050</guid>
      <dc:creator>awalesa</dc:creator>
      <dc:date>2012-01-25T10:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexer is not sending to syslog - please help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56723#M11051</link>
      <description>&lt;P&gt;But why do you need the syslog functionality at the end? is that just where you have all your other logs centralised? Also you can just click on comment below this instead of doing another answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2012 10:51:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56723#M11051</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-01-25T10:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexer is not sending to syslog - please help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56724#M11052</link>
      <description>&lt;P&gt;Sorry &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I want to try to use OSSIM at the end to warn on anomalies&lt;/P&gt;

&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2012 10:55:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-is-not-sending-to-syslog-please-help/m-p/56724#M11052</guid>
      <dc:creator>awalesa</dc:creator>
      <dc:date>2012-01-25T10:55:55Z</dc:date>
    </item>
  </channel>
</rss>

