<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reading log4j from syslog files in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Reading-log4j-from-syslog-files/m-p/85488#M17771</link>
    <description>&lt;P&gt;I strayed away from using the syslogappender and just installed universal forwarders where ever the log4j data was that I wanted to get at, just made things a bit cleaner.  Whats your hesitation? why the need to read from syslog?&lt;/P&gt;</description>
    <pubDate>Wed, 27 Jun 2012 21:35:22 GMT</pubDate>
    <dc:creator>joshd</dc:creator>
    <dc:date>2012-06-27T21:35:22Z</dc:date>
    <item>
      <title>Reading log4j from syslog files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Reading-log4j-from-syslog-files/m-p/85487#M17770</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;testing out Splunk, and wondering is there some kind of out-of-the-box solution to correctly process syslog files that were created from log4j SyslogAppender?&lt;/P&gt;

&lt;P&gt;I've tried to follow the guide &lt;A href="http://wiki.splunk.com/Community:StripSyslog"&gt;http://wiki.splunk.com/Community:StripSyslog&lt;/A&gt;, but unfortunetally it does not work.&lt;/P&gt;

&lt;P&gt;I'm using log pattern specified in &lt;A href="http://wiki.apache.org/logging-log4j/syslog"&gt;http://wiki.apache.org/logging-log4j/syslog&lt;/A&gt; :&lt;BR /&gt;&lt;BR /&gt;
%t %5r %-5p %-21d{yyyyMMdd HH:mm:ss,SSS} %c{2} [%x] %m %n&lt;/P&gt;

&lt;P&gt;Should i use another pattern?&lt;/P&gt;

&lt;P&gt;Note: i do not want to log directly from log4j to splunk, i want splunk to read from syslog.&lt;BR /&gt;
Are there any working solutions?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2012 21:30:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Reading-log4j-from-syslog-files/m-p/85487#M17770</guid>
      <dc:creator>gerasalus</dc:creator>
      <dc:date>2012-06-27T21:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: Reading log4j from syslog files</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Reading-log4j-from-syslog-files/m-p/85488#M17771</link>
      <description>&lt;P&gt;I strayed away from using the syslogappender and just installed universal forwarders where ever the log4j data was that I wanted to get at, just made things a bit cleaner.  Whats your hesitation? why the need to read from syslog?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jun 2012 21:35:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Reading-log4j-from-syslog-files/m-p/85488#M17771</guid>
      <dc:creator>joshd</dc:creator>
      <dc:date>2012-06-27T21:35:22Z</dc:date>
    </item>
  </channel>
</rss>

