<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sending syslog without any header in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Sending-syslog-without-any-header/m-p/96166#M20026</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;

&lt;P&gt;When a firwall logs go to the Splunk and the Splunk redirects to our log collector, additional timestamp and syslog headers to the packet. It makes the logs indecipherable once they reach our log collector. &lt;/P&gt;

&lt;P&gt;Any solution passing logs without any log format changes?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jan 2013 06:28:17 GMT</pubDate>
    <dc:creator>hswoo2000</dc:creator>
    <dc:date>2013-01-23T06:28:17Z</dc:date>
    <item>
      <title>Sending syslog without any header</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sending-syslog-without-any-header/m-p/96166#M20026</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;

&lt;P&gt;When a firwall logs go to the Splunk and the Splunk redirects to our log collector, additional timestamp and syslog headers to the packet. It makes the logs indecipherable once they reach our log collector. &lt;/P&gt;

&lt;P&gt;Any solution passing logs without any log format changes?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 06:28:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sending-syslog-without-any-header/m-p/96166#M20026</guid>
      <dc:creator>hswoo2000</dc:creator>
      <dc:date>2013-01-23T06:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: Sending syslog without any header</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sending-syslog-without-any-header/m-p/96167#M20027</link>
      <description>&lt;P&gt;You can use the setting in Splunk inputs.conf &lt;CODE&gt;no_appending_timestamp&lt;/CODE&gt;. See the README file or docs for inputs.conf.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 07:31:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sending-syslog-without-any-header/m-p/96167#M20027</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2013-01-23T07:31:29Z</dc:date>
    </item>
  </channel>
</rss>

