<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Forwarding all events from a Splunk Instance in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-all-events-from-a-Splunk-Instance/m-p/58682#M11544</link>
    <description>&lt;P&gt;I am using Splunk to collect logs from a diverse environment.  The same events, or at least a large subset, need to be forwarded to security event integration management device. What I want to avoid is having a Windows server send logs to two security devices - Splunk and the security event manager.  Is it possible to have Splunk collect while also forwarding?&lt;/P&gt;</description>
    <pubDate>Tue, 15 Mar 2011 00:46:47 GMT</pubDate>
    <dc:creator>npatellis</dc:creator>
    <dc:date>2011-03-15T00:46:47Z</dc:date>
    <item>
      <title>Forwarding all events from a Splunk Instance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-all-events-from-a-Splunk-Instance/m-p/58682#M11544</link>
      <description>&lt;P&gt;I am using Splunk to collect logs from a diverse environment.  The same events, or at least a large subset, need to be forwarded to security event integration management device. What I want to avoid is having a Windows server send logs to two security devices - Splunk and the security event manager.  Is it possible to have Splunk collect while also forwarding?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2011 00:46:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-all-events-from-a-Splunk-Instance/m-p/58682#M11544</guid>
      <dc:creator>npatellis</dc:creator>
      <dc:date>2011-03-15T00:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding all events from a Splunk Instance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarding-all-events-from-a-Splunk-Instance/m-p/58683#M11545</link>
      <description>&lt;P&gt;Yes it is. This link should lead you in the right direction.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/4.1.6/Admin/Forwarddatatothird-partysystems" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.6/Admin/Forwarddatatothird-partysystems&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I am forwarding almost all of our data to an IDS. We did filter some junk out prior to being indexed or forwarded. The following link will help you filter out some of the data that you do not want to forward.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/4.1.5/Admin/Routeandfilterdata#Filter_event_data_and_send_to_queues" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.5/Admin/Routeandfilterdata#Filter_event_data_and_send_to_queues&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I-Man&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2011 00:58:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarding-all-events-from-a-Splunk-Instance/m-p/58683#M11545</guid>
      <dc:creator>I-Man</dc:creator>
      <dc:date>2011-03-15T00:58:21Z</dc:date>
    </item>
  </channel>
</rss>

