<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Possible to clone/forward logs to a third-party system? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Possible-to-clone-forward-logs-to-a-third-party-system/m-p/136329#M28086</link>
    <description>&lt;P&gt;Thanks for the quick replies guys.&lt;BR /&gt;
I have looked into this doc but I couldn´t see anywhere if the data is "copied" when forwarded or not.&lt;BR /&gt;
I would like to have the data on two locations so to speak. Not just routed or forwarded away all together from the Splunk indexer.&lt;BR /&gt;
If you understand what I mean. &lt;BR /&gt;
But if this is possible with the forwarding described in the document, then I will start looking into implementing this.&lt;/P&gt;

&lt;P&gt;/CJ&lt;/P&gt;</description>
    <pubDate>Thu, 27 Nov 2014 12:46:37 GMT</pubDate>
    <dc:creator>chje</dc:creator>
    <dc:date>2014-11-27T12:46:37Z</dc:date>
    <item>
      <title>Possible to clone/forward logs to a third-party system?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Possible-to-clone-forward-logs-to-a-third-party-system/m-p/136326#M28083</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
Is it possible to clone/forward logevents from specific hosts from a Splunk instance to a third-party system?&lt;BR /&gt;
The importance here is that all logs still should be indexed and searchable on the splunk indexer but some of the data should also be copied from the indexer and get forwarded to a third-party system. This third-party system is a syslog-ng.&lt;BR /&gt;
Which approach should I look into more deeply? To forward the data or to clone the data?&lt;BR /&gt;
Is cloning even possible to a no-splunk instance?&lt;BR /&gt;
Thanks in advance.&lt;/P&gt;

&lt;P&gt;Br,&lt;BR /&gt;
CJ&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2014 12:37:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Possible-to-clone-forward-logs-to-a-third-party-system/m-p/136326#M28083</guid>
      <dc:creator>chje</dc:creator>
      <dc:date>2014-11-27T12:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to clone/forward logs to a third-party system?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Possible-to-clone-forward-logs-to-a-third-party-system/m-p/136327#M28084</link>
      <description>&lt;P&gt;Hi chje,&lt;/P&gt;

&lt;P&gt;read the docs about &lt;CODE&gt;Forward data to third-party systems&lt;/CODE&gt; &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Forwarddatatothird-partysystemsd"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Forwarddatatothird-partysystemsd&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2014 12:39:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Possible-to-clone-forward-logs-to-a-third-party-system/m-p/136327#M28084</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-11-27T12:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to clone/forward logs to a third-party system?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Possible-to-clone-forward-logs-to-a-third-party-system/m-p/136328#M28085</link>
      <description>&lt;P&gt;you can forward data to third party system and this is the better approach, see this link&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Forwarddatatothird-partysystemsd"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Forwarddatatothird-partysystemsd&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2014 12:40:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Possible-to-clone-forward-logs-to-a-third-party-system/m-p/136328#M28085</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2014-11-27T12:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to clone/forward logs to a third-party system?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Possible-to-clone-forward-logs-to-a-third-party-system/m-p/136329#M28086</link>
      <description>&lt;P&gt;Thanks for the quick replies guys.&lt;BR /&gt;
I have looked into this doc but I couldn´t see anywhere if the data is "copied" when forwarded or not.&lt;BR /&gt;
I would like to have the data on two locations so to speak. Not just routed or forwarded away all together from the Splunk indexer.&lt;BR /&gt;
If you understand what I mean. &lt;BR /&gt;
But if this is possible with the forwarding described in the document, then I will start looking into implementing this.&lt;/P&gt;

&lt;P&gt;/CJ&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2014 12:46:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Possible-to-clone-forward-logs-to-a-third-party-system/m-p/136329#M28086</guid>
      <dc:creator>chje</dc:creator>
      <dc:date>2014-11-27T12:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to clone/forward logs to a third-party system?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Possible-to-clone-forward-logs-to-a-third-party-system/m-p/136330#M28087</link>
      <description>&lt;P&gt;Okay, follow the docs and add this in your &lt;CODE&gt;outputs.conf&lt;/CODE&gt; &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;indexAndForward = [true|false]
* Index all data locally, in addition to forwarding it.
* This is known as an "index-and-forward" configuration.
* This attribute is available only at the top level [tcpout] stanza. It cannot be overridden in a target group.
* Defaults to false.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 27 Nov 2014 12:53:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Possible-to-clone-forward-logs-to-a-third-party-system/m-p/136330#M28087</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-11-27T12:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to clone/forward logs to a third-party system?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Possible-to-clone-forward-logs-to-a-third-party-system/m-p/136331#M28088</link>
      <description>&lt;P&gt;or in the UI&lt;/P&gt;

&lt;P&gt;Settings » Forwarding and receiving » Forwarding defaults&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Store a local copy of forwarded events?
 Yes   No
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 27 Nov 2014 12:55:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Possible-to-clone-forward-logs-to-a-third-party-system/m-p/136331#M28088</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-11-27T12:55:24Z</dc:date>
    </item>
  </channel>
</rss>

