<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure index and application in Universal forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99522#M20819</link>
    <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Routeandfilterdatad#Discard_specific_events_and_keep_the_rest"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Routeandfilterdatad#Discard_specific_events_and_keep_the_rest&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Apr 2013 10:54:49 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2013-04-19T10:54:49Z</dc:date>
    <item>
      <title>Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99510#M20807</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I configured Universal forwarder to push the windows event logs ( adfs logs ) to main splunk server.&lt;/P&gt;

&lt;P&gt;Can anyone help me how to configure the application and indexer.&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 12:18:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99510#M20807</guid>
      <dc:creator>skomath</dc:creator>
      <dc:date>2013-04-18T12:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99511#M20808</link>
      <description>&lt;P&gt;Platform : windows&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 13:47:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99511#M20808</guid>
      <dc:creator>skomath</dc:creator>
      <dc:date>2013-04-18T13:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99512#M20809</link>
      <description>&lt;P&gt;A little more information would be helpful .... what app, what index, what specifically do you need help with?  You might want to take a look at the Splunk App for Active Directory (&lt;A href="http://splunk-base.splunk.com/apps/51338/splunk-app-for-active-directory"&gt;http://splunk-base.splunk.com/apps/51338/splunk-app-for-active-directory&lt;/A&gt;) as it will do most of the configuration for you.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 14:04:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99512#M20809</guid>
      <dc:creator>jstockamp</dc:creator>
      <dc:date>2013-04-18T14:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99513#M20810</link>
      <description>&lt;P&gt;In splunk web we can add new application ( say myApp ) right. And I created new index as well ( called myIndex). And the in our application server I installed unversal forwarder and configured to push adfs logs. Logs are moving to main index.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 14:10:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99513#M20810</guid>
      <dc:creator>skomath</dc:creator>
      <dc:date>2013-04-18T14:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99514#M20811</link>
      <description>&lt;P&gt;Do you want any more details ?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 14:13:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99514#M20811</guid>
      <dc:creator>skomath</dc:creator>
      <dc:date>2013-04-18T14:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99515#M20812</link>
      <description>&lt;P&gt;I want to move all logs to specific index ( say myIndex ) rather than going to main index&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 14:16:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99515#M20812</guid>
      <dc:creator>skomath</dc:creator>
      <dc:date>2013-04-18T14:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99516#M20813</link>
      <description>&lt;P&gt;Wev are looking for the ADFS monitoring. Splunk App for Active Directory supports ADFS ?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 14:21:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99516#M20813</guid>
      <dc:creator>skomath</dc:creator>
      <dc:date>2013-04-18T14:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99517#M20814</link>
      <description>&lt;P&gt;To specify the index you want an input to go to just add:&lt;/P&gt;

&lt;P&gt;index=myIndex&lt;/P&gt;

&lt;P&gt;to the monitor stanza in your inputs.conf (on the forwarder).&lt;/P&gt;

&lt;P&gt;I don't believe Splunk for AD supports ADFS logs specifically.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 14:33:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99517#M20814</guid>
      <dc:creator>jstockamp</dc:creator>
      <dc:date>2013-04-18T14:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99518#M20815</link>
      <description>&lt;P&gt;which location ? which file, Is it inputs.conf ?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 14:38:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99518#M20815</guid>
      <dc:creator>skomath</dc:creator>
      <dc:date>2013-04-18T14:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99519#M20816</link>
      <description>&lt;P&gt;It sounds like you were already configured the forwarder to push ADFS logs (which means you configured an inputs.conf file to monitor a directory).  In that inputs.conf add index=myIndex and you should be good.  there can be multiple inputs.conf files on a forwarder, so you could have configured it in a number of places.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 14:43:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99519#M20816</guid>
      <dc:creator>jstockamp</dc:creator>
      <dc:date>2013-04-18T14:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99520#M20817</link>
      <description>&lt;P&gt;ADFS will write the logs into windows event log. I configured the unversal forwarder to collect log from the windows event log. For installation I used the windows msi setup.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2013 06:16:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99520#M20817</guid>
      <dc:creator>skomath</dc:creator>
      <dc:date>2013-04-19T06:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99521#M20818</link>
      <description>&lt;P&gt;I specified like this&lt;/P&gt;

&lt;P&gt;[WinEventLog:Security]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
index = myIndex&lt;BR /&gt;
All the security logs start moving to the specified index.&lt;/P&gt;

&lt;P&gt;Now the problem is... I want to filter the security logs before pushing to the server. Like I want to push only the logs having SourceName=AD FS 2.0 Auditing&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2013 09:43:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99521#M20818</guid>
      <dc:creator>skomath</dc:creator>
      <dc:date>2013-04-19T09:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99522#M20819</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Routeandfilterdatad#Discard_specific_events_and_keep_the_rest"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Routeandfilterdatad#Discard_specific_events_and_keep_the_rest&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2013 10:54:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99522#M20819</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-04-19T10:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99523#M20820</link>
      <description>&lt;P&gt;Just to be clear these modifications to props.conf and transforms.conf will go on the indexer, not the forwarder.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2013 13:45:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99523#M20820</guid>
      <dc:creator>jstockamp</dc:creator>
      <dc:date>2013-04-19T13:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99524#M20821</link>
      <description>&lt;P&gt;So, Is it possible to do the filtering at client side ( in Universal forwarder ) ?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2013 14:57:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99524#M20821</guid>
      <dc:creator>skomath</dc:creator>
      <dc:date>2013-04-19T14:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99525#M20822</link>
      <description>&lt;P&gt;see &lt;A href="http://splunk-base.splunk.com/answers/39231/filtering-with-a-uf-before-indexing"&gt;http://splunk-base.splunk.com/answers/39231/filtering-with-a-uf-before-indexing&lt;/A&gt; for answers to your above question&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2013 15:16:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99525#M20822</guid>
      <dc:creator>aholzer</dc:creator>
      <dc:date>2013-04-19T15:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: Configure index and application in Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99526#M20823</link>
      <description>&lt;P&gt;No, it is not.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2013 15:16:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configure-index-and-application-in-Universal-forwarder/m-p/99526#M20823</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-04-19T15:16:36Z</dc:date>
    </item>
  </channel>
</rss>

