<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to schedule a saved search to forward Syslog events or do I have to use REGEX in transforms.conf? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-schedule-a-saved-search-to-forward-Syslog/m-p/126656#M26061</link>
    <description>&lt;P&gt;I will give it a try. Thanks for your input!&lt;/P&gt;</description>
    <pubDate>Wed, 04 Feb 2015 11:59:45 GMT</pubDate>
    <dc:creator>zugji</dc:creator>
    <dc:date>2015-02-04T11:59:45Z</dc:date>
    <item>
      <title>Is it possible to schedule a saved search to forward Syslog events or do I have to use REGEX in transforms.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-schedule-a-saved-search-to-forward-Syslog/m-p/126652#M26057</link>
      <description>&lt;P&gt;In our splunk environment, we collect and index all syslog messages from our network elements. Some of the syslog messages we would like to forward to another system by syslog protocol (UDP/514). I know it is possible to route syslog messages to another system. As we get about 1 million syslog messages per day we would like to filter the most of them to prevent flooding the target host. &lt;/P&gt;

&lt;P&gt;Is that possible with a saved search scheduling every minute or do I have to use the REGEX value in the transforms.conf configuration file?&lt;/P&gt;

&lt;P&gt;Our environment.&lt;BR /&gt;
Splunk 6.2.1&lt;BR /&gt;
OS: Solaris X86&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Christain&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2015 08:23:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-schedule-a-saved-search-to-forward-Syslog/m-p/126652#M26057</guid>
      <dc:creator>zugji</dc:creator>
      <dc:date>2015-02-04T08:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to schedule a saved search to forward Syslog events or do I have to use REGEX in transforms.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-schedule-a-saved-search-to-forward-Syslog/m-p/126653#M26058</link>
      <description>&lt;P&gt;Hi zugji,&lt;/P&gt;

&lt;P&gt;using the REGEX in &lt;CODE&gt;transforms.conf&lt;/CODE&gt; is the way to go. &lt;BR /&gt;
You &lt;EM&gt;could&lt;/EM&gt; do it by using a saved search and some custom search command, which takes the search result and pushes it out to the other syslog receiver....But, as you can image this will need some heavy coding.&lt;/P&gt;

&lt;P&gt;So, using the REGEX in &lt;CODE&gt;transforms.conf&lt;/CODE&gt; is simple, easy, faster and available right now.&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2015 09:13:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-schedule-a-saved-search-to-forward-Syslog/m-p/126653#M26058</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-02-04T09:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to schedule a saved search to forward Syslog events or do I have to use REGEX in transforms.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-schedule-a-saved-search-to-forward-Syslog/m-p/126654#M26059</link>
      <description>&lt;P&gt;Hello MuS&lt;BR /&gt;
Thanks a lot for your answer. Our saved search to get the needed messages out is a little bit complicate. I think it would be easier to have a saved search running and doing the job. Here is the search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=* NOT sourcetype=stash| regex _raw="Closed telnet|OSAPI-5-CLEAN_TASK:\s*osapi_task.c:(?:.*)cleaning\s*up\s*exited\s*task|SYS-6-CFG_CHG.*?/(\S+)/|bsnConfigurationSavedToNvram|SYS-5-RELOAD|SYS-5-RESTART|#\d+ Session closed|%CONFIG|SYSLOG_CONFIG|Connection logout|user.*connected from|CLM: Logout|configure changed|System restarted|AAA-5-AAA_AUTH_ADMIN_USER: aaa.(.*)[\t ]for[\t ]admin[\t ]user[\t ]'(.*)'|SYS-5-CONFIG_I|SYSTEM_RESET|entering configuration mode|UI_COMMIT|SYS-6-CFG|10HWCM|User \S+ authenticated|Authentication succeeded|Session logged out|CLM: Login|Save config|Successful connection|user:.*command:|VTY login from|exiting configuration mode|User \S+ executed the [\S\s]+ command|VTY logout from"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Christian&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2015 09:25:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-schedule-a-saved-search-to-forward-Syslog/m-p/126654#M26059</guid>
      <dc:creator>zugji</dc:creator>
      <dc:date>2015-02-04T09:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to schedule a saved search to forward Syslog events or do I have to use REGEX in transforms.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-schedule-a-saved-search-to-forward-Syslog/m-p/126655#M26060</link>
      <description>&lt;P&gt;This basically just one big regex which could be used in the transforms.conf .... needs testing anyway, so why not use the existing Splunk internal features?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2015 10:30:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-schedule-a-saved-search-to-forward-Syslog/m-p/126655#M26060</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-02-04T10:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to schedule a saved search to forward Syslog events or do I have to use REGEX in transforms.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-schedule-a-saved-search-to-forward-Syslog/m-p/126656#M26061</link>
      <description>&lt;P&gt;I will give it a try. Thanks for your input!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2015 11:59:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-schedule-a-saved-search-to-forward-Syslog/m-p/126656#M26061</guid>
      <dc:creator>zugji</dc:creator>
      <dc:date>2015-02-04T11:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to schedule a saved search to forward Syslog events or do I have to use REGEX in transforms.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-schedule-a-saved-search-to-forward-Syslog/m-p/126657#M26062</link>
      <description>&lt;P&gt;Finally I found a solution to reach my goal.&lt;/P&gt;

&lt;P&gt;First define your search xy and enable summary for the search which is in my environment scheduled every minute.&lt;BR /&gt;
After that you can search the result by using the summary index.&lt;BR /&gt;
The events in this summary index has the source name equal to the saved search xy. &lt;/P&gt;

&lt;P&gt;savedsearch.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[xy]
search=...
action.summary_index = 1
action.summary_index._name = thirdparty
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::xy]
TRANSFORMS-routing = forward_xy
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[forward_xy]
REGEX = .
DEST_KEY = _SYSLOG_ROUTING
FORMAT = forward-host
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;outputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[syslog:forward-host]
server = a.b.c.d:514
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Christian&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2015 12:36:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-schedule-a-saved-search-to-forward-Syslog/m-p/126657#M26062</guid>
      <dc:creator>zugji</dc:creator>
      <dc:date>2015-03-05T12:36:58Z</dc:date>
    </item>
  </channel>
</rss>

