<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can universal forwarders detect and forward newly created logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-universal-forwarders-detect-and-forward-newly-created-logs/m-p/81884#M16909</link>
    <description>&lt;P&gt;Can Splunk universal forwarders handle and forward newly created log files?
I would like to forward data as raw logs to a remote server and not a splunk indexer using the splunk forwarder, but is it smart enough to trigger upon file creation?&lt;/P&gt;</description>
    <pubDate>Fri, 15 Apr 2011 01:05:47 GMT</pubDate>
    <dc:creator>suhprano</dc:creator>
    <dc:date>2011-04-15T01:05:47Z</dc:date>
    <item>
      <title>Can universal forwarders detect and forward newly created logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-universal-forwarders-detect-and-forward-newly-created-logs/m-p/81884#M16909</link>
      <description>&lt;P&gt;Can Splunk universal forwarders handle and forward newly created log files?
I would like to forward data as raw logs to a remote server and not a splunk indexer using the splunk forwarder, but is it smart enough to trigger upon file creation?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2011 01:05:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-universal-forwarders-detect-and-forward-newly-created-logs/m-p/81884#M16909</guid>
      <dc:creator>suhprano</dc:creator>
      <dc:date>2011-04-15T01:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: Can universal forwarders detect and forward newly created logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-universal-forwarders-detect-and-forward-newly-created-logs/m-p/81885#M16910</link>
      <description>&lt;P&gt;if you specify a directory in the inputs.conf being used by the forwarder in question, and the log file is created in that directory, it will get forwarded automatically. &lt;/P&gt;

&lt;P&gt;for details about how Splunk monitors files and directories: 
&lt;A href="http://www.splunk.com/base/Documentation/latest/Data/Monitorfilesanddirectories" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Data/Monitorfilesanddirectories&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;details on how forwarders can get data:
&lt;A href="http://www.splunk.com/base/Documentation/latest/Data/Usingforwardingagents" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Data/Usingforwardingagents&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;i missed that you were talking about forwarding to a third-party (not splunk) host, here is the info for that:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/latest/Deploy/Forwarddatatothird-partysystemsd" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Deploy/Forwarddatatothird-partysystemsd&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2011 02:02:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-universal-forwarders-detect-and-forward-newly-created-logs/m-p/81885#M16910</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2011-04-15T02:02:52Z</dc:date>
    </item>
  </channel>
</rss>

