<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sending Splunk Data to Syslog Server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Sending-Splunk-Data-to-Syslog-Server/m-p/127098#M26151</link>
    <description>&lt;P&gt;I have Splunk receiving data from various sources, but I would like to be able to send that data on to another syslog collector.  I have read that various documents on how this should be achieved and I have added the following to the outputs.conf &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;[syslog:my_syslog_group]&lt;BR /&gt;
server = 192.168.1.1:514&lt;BR /&gt;
type = udp&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Yet the data is not getting sent to that collector.  This new collector is actually running on the same host as Splunk, but is using the default syslog port of UDP/514 where as Splunk is using a different port.&lt;/P&gt;

&lt;P&gt;Firewalls are not causing the problem as I have tested this with the firewalls disabled.&lt;/P&gt;

&lt;P&gt;What else do I need to do to make this work?&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 15:11:23 GMT</pubDate>
    <dc:creator>balcv</dc:creator>
    <dc:date>2020-09-28T15:11:23Z</dc:date>
    <item>
      <title>Sending Splunk Data to Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sending-Splunk-Data-to-Syslog-Server/m-p/127098#M26151</link>
      <description>&lt;P&gt;I have Splunk receiving data from various sources, but I would like to be able to send that data on to another syslog collector.  I have read that various documents on how this should be achieved and I have added the following to the outputs.conf &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;[syslog:my_syslog_group]&lt;BR /&gt;
server = 192.168.1.1:514&lt;BR /&gt;
type = udp&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Yet the data is not getting sent to that collector.  This new collector is actually running on the same host as Splunk, but is using the default syslog port of UDP/514 where as Splunk is using a different port.&lt;/P&gt;

&lt;P&gt;Firewalls are not causing the problem as I have tested this with the firewalls disabled.&lt;/P&gt;

&lt;P&gt;What else do I need to do to make this work?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:11:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sending-Splunk-Data-to-Syslog-Server/m-p/127098#M26151</guid>
      <dc:creator>balcv</dc:creator>
      <dc:date>2020-09-28T15:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: Sending Splunk Data to Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sending-Splunk-Data-to-Syslog-Server/m-p/127099#M26152</link>
      <description>&lt;P&gt;Is this a full-blown Splunk instance (indexer or likewise) or a Universal Forwarder?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2013 07:44:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sending-Splunk-Data-to-Syslog-Server/m-p/127099#M26152</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-11-04T07:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: Sending Splunk Data to Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sending-Splunk-Data-to-Syslog-Server/m-p/127100#M26153</link>
      <description>&lt;P&gt;If you use a free license this feature is disabled. (I'm pretty sure but not 100%)&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2013 09:53:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sending-Splunk-Data-to-Syslog-Server/m-p/127100#M26153</guid>
      <dc:creator>sbaryakov</dc:creator>
      <dc:date>2013-11-04T09:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: Sending Splunk Data to Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sending-Splunk-Data-to-Syslog-Server/m-p/127101#M26154</link>
      <description>&lt;P&gt;Thank you. Yes I have had to revert to the Free License so that explains it.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2013 22:09:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sending-Splunk-Data-to-Syslog-Server/m-p/127101#M26154</guid>
      <dc:creator>balcv</dc:creator>
      <dc:date>2013-11-04T22:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Sending Splunk Data to Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sending-Splunk-Data-to-Syslog-Server/m-p/127102#M26155</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
   I have similar probelm , so I use non-license splunk(it should be as your mean ==&amp;gt;free license), whether I only send TCPData but could not send syslog , right ??&lt;/P&gt;

&lt;P&gt;wyldkao&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2014 07:29:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sending-Splunk-Data-to-Syslog-Server/m-p/127102#M26155</guid>
      <dc:creator>wyldkao</dc:creator>
      <dc:date>2014-04-17T07:29:30Z</dc:date>
    </item>
  </channel>
</rss>

