<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Splunk Forwarder on syslog server to forward to splunk server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-Forwarder-on-syslog-server-to-forward-to-splunk/m-p/87259#M18105</link>
    <description>&lt;P&gt;so i just need to configure receiving index for splunk forwarder to 9997&lt;/P&gt;

&lt;P&gt;for the syslog server, splunk forwarder automatically gets its data from syslog? (I don't need to do any config to syslog to forward the logs to splunk forwarder)?&lt;/P&gt;</description>
    <pubDate>Tue, 09 Apr 2013 01:17:11 GMT</pubDate>
    <dc:creator>oranger1426</dc:creator>
    <dc:date>2013-04-09T01:17:11Z</dc:date>
    <item>
      <title>Using Splunk Forwarder on syslog server to forward to splunk server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-Forwarder-on-syslog-server-to-forward-to-splunk/m-p/87257#M18103</link>
      <description>&lt;P&gt;Syslogs already has all the logs from other server using snare udp 514&lt;/P&gt;

&lt;P&gt;Do I need to configure anything on the splunk forwarder to get logs from syslog?&lt;/P&gt;

&lt;P&gt;Or it gets the syslogs on the syslog server automatically?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2013 10:27:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-Forwarder-on-syslog-server-to-forward-to-splunk/m-p/87257#M18103</guid>
      <dc:creator>oranger1426</dc:creator>
      <dc:date>2013-04-08T10:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Forwarder on syslog server to forward to splunk server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-Forwarder-on-syslog-server-to-forward-to-splunk/m-p/87258#M18104</link>
      <description>&lt;P&gt;You can point any syslog towards the splunk server and configure the splunk server to receive syslog. So you can point snare to splunk, but you need to configure a receiving port first.&lt;/P&gt;

&lt;P&gt;Or you can have a splunk forwarder índex the files on the syslog server and send it to splunk.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2013 14:30:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-Forwarder-on-syslog-server-to-forward-to-splunk/m-p/87258#M18104</guid>
      <dc:creator>krugger</dc:creator>
      <dc:date>2013-04-08T14:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Forwarder on syslog server to forward to splunk server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-Forwarder-on-syslog-server-to-forward-to-splunk/m-p/87259#M18105</link>
      <description>&lt;P&gt;so i just need to configure receiving index for splunk forwarder to 9997&lt;/P&gt;

&lt;P&gt;for the syslog server, splunk forwarder automatically gets its data from syslog? (I don't need to do any config to syslog to forward the logs to splunk forwarder)?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2013 01:17:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-Forwarder-on-syslog-server-to-forward-to-splunk/m-p/87259#M18105</guid>
      <dc:creator>oranger1426</dc:creator>
      <dc:date>2013-04-09T01:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk Forwarder on syslog server to forward to splunk server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-Forwarder-on-syslog-server-to-forward-to-splunk/m-p/87260#M18106</link>
      <description>&lt;P&gt;You'd need to set up your data inputs under&lt;/P&gt;

&lt;P&gt;manager -&amp;gt; data inputs -&amp;gt; UDP -&amp;gt; NEW&lt;/P&gt;

&lt;P&gt;From there you just add the port you want to use and point your syslog server to the port on the splunk server.  However, if you have an agent running on the syslog server, it might be better to get syslog to pump the file to disk and read that.  Doing that ensures that you don't lose any data if the splunk server goes down or if the network has issues.  Otherwise, you can just share the drive to the splunk server and let Splunk pick it up as a local file.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2013 03:05:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-Forwarder-on-syslog-server-to-forward-to-splunk/m-p/87260#M18106</guid>
      <dc:creator>stephenho</dc:creator>
      <dc:date>2013-04-09T03:05:23Z</dc:date>
    </item>
  </channel>
</rss>

