<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Newbie in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Newbie/m-p/91351#M18992</link>
    <description>&lt;P&gt;For a "newbie" it will be simplest to setup a seperate data input for each source.&lt;BR /&gt;
However it is also possible to use the same data input and dynamically set the index based on the content or source, host etc... of the incoming data (using props.conf and transforms.conf)&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jul 2013 19:05:28 GMT</pubDate>
    <dc:creator>Damien_Dallimor</dc:creator>
    <dc:date>2013-07-10T19:05:28Z</dc:date>
    <item>
      <title>Splunk Newbie</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Newbie/m-p/91348#M18989</link>
      <description>&lt;P&gt;I am far from being an advanced user of splunk and as a result have a question that I would imagine would be quite simple.  What we have used Splunk for up to now, is to dump some of our HP Blade components logs into a syslog server so that we can generate alerts if something happens.  &lt;/P&gt;

&lt;P&gt;Now, I have other logs that I would like to send into splunk, however I want to separate my HP component logs from these new logs.  Is this possible?  &lt;/P&gt;

&lt;P&gt;I would also like to grant access to a specific group of users to see these new logs....but I don't want them to see anything else (The HP Blade logs).&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2013 16:13:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Newbie/m-p/91348#M18989</guid>
      <dc:creator>MichaelBernas</dc:creator>
      <dc:date>2013-07-10T16:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Newbie</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Newbie/m-p/91349#M18990</link>
      <description>&lt;P&gt;Put the HP logs and the new logs in their own &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.3/Indexer/HowSplunkstoresindexes"&gt;Splunk Indexes&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Then use &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Security/UseaccesscontroltosecureSplunkdata"&gt;role based permissions&lt;/A&gt; to determine which roles have visibility of those indexes.&lt;/P&gt;

&lt;P&gt;Then &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Security/Aboutusersandroles"&gt;assign users to the appropriate role&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2013 16:27:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Newbie/m-p/91349#M18990</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2013-07-10T16:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Newbie</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Newbie/m-p/91350#M18991</link>
      <description>&lt;P&gt;Thanks for the quick response!!&lt;/P&gt;

&lt;P&gt;So I have all this now. For the role, I copied the basic user role, however gave it access to search the new index that I created.&lt;/P&gt;

&lt;P&gt;Another dumb question...I just want to verify that I need to create a separate data input using a different port for these logs and make sure that it is set to the index that I created...is that correct?&lt;/P&gt;

&lt;P&gt;Thanks!!&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2013 18:58:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Newbie/m-p/91350#M18991</guid>
      <dc:creator>MichaelBernas</dc:creator>
      <dc:date>2013-07-10T18:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Newbie</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Newbie/m-p/91351#M18992</link>
      <description>&lt;P&gt;For a "newbie" it will be simplest to setup a seperate data input for each source.&lt;BR /&gt;
However it is also possible to use the same data input and dynamically set the index based on the content or source, host etc... of the incoming data (using props.conf and transforms.conf)&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2013 19:05:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Newbie/m-p/91351#M18992</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2013-07-10T19:05:28Z</dc:date>
    </item>
  </channel>
</rss>

