<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What tips or documentation can help me with a first time Splunk setup of three different types of syslog coming in: Firewall, Windows and Linux? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-tips-or-documentation-can-help-me-with-a-first-time-Splunk/m-p/152012#M30935</link>
    <description>&lt;P&gt;Greetings --  Long time user, first-time SysAdmin (of SPLUNK)  I'm sure this is documented, but can someone point me to the specific info I need, or supply some tips?   I can read about all this just fine, if someone can point me at the specific docs needed...&lt;/P&gt;

&lt;P&gt;1.) I have three different types of Syslog coming in;  Firewall, Windows, and Linux.   I guess this means I need three different SourceTypes, so a different set of Interesting Fields is pulled out for each?  How do I create 3 custom SourceTypes each with its own set of Interesting Fields...?&lt;/P&gt;

&lt;P&gt;2.) I need to store the raw syslog data for my Firewalls, Windows &amp;amp; Linux machines  on the SPLUNK server, so it can be viewed by auditors.  How do I configure that?   --How can I configure aging / archiving of these syslog entries?  (three different directory paths for three different types of syslog)&lt;/P&gt;

&lt;P&gt;3.) I currently am using one SourceType, and I have a single firewall  using it.   I'm displaying way more Interesting Fields than what I need.  For instance, I'm displaying "hours", and all  my entries have 24 values (zero through 23) ; this is useless.  How can I get SPLUNK to stop spinning CPU cycles, indexing data on useless fields?   There's a good chance I'll be forced to do this on a Virtual Machine, so I only want SPLUNK spending I/O on fields that I say are interesting...&lt;/P&gt;

&lt;P&gt;THanks!&lt;/P&gt;</description>
    <pubDate>Tue, 16 Dec 2014 19:12:31 GMT</pubDate>
    <dc:creator>batsona</dc:creator>
    <dc:date>2014-12-16T19:12:31Z</dc:date>
    <item>
      <title>What tips or documentation can help me with a first time Splunk setup of three different types of syslog coming in: Firewall, Windows and Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-tips-or-documentation-can-help-me-with-a-first-time-Splunk/m-p/152012#M30935</link>
      <description>&lt;P&gt;Greetings --  Long time user, first-time SysAdmin (of SPLUNK)  I'm sure this is documented, but can someone point me to the specific info I need, or supply some tips?   I can read about all this just fine, if someone can point me at the specific docs needed...&lt;/P&gt;

&lt;P&gt;1.) I have three different types of Syslog coming in;  Firewall, Windows, and Linux.   I guess this means I need three different SourceTypes, so a different set of Interesting Fields is pulled out for each?  How do I create 3 custom SourceTypes each with its own set of Interesting Fields...?&lt;/P&gt;

&lt;P&gt;2.) I need to store the raw syslog data for my Firewalls, Windows &amp;amp; Linux machines  on the SPLUNK server, so it can be viewed by auditors.  How do I configure that?   --How can I configure aging / archiving of these syslog entries?  (three different directory paths for three different types of syslog)&lt;/P&gt;

&lt;P&gt;3.) I currently am using one SourceType, and I have a single firewall  using it.   I'm displaying way more Interesting Fields than what I need.  For instance, I'm displaying "hours", and all  my entries have 24 values (zero through 23) ; this is useless.  How can I get SPLUNK to stop spinning CPU cycles, indexing data on useless fields?   There's a good chance I'll be forced to do this on a Virtual Machine, so I only want SPLUNK spending I/O on fields that I say are interesting...&lt;/P&gt;

&lt;P&gt;THanks!&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2014 19:12:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-tips-or-documentation-can-help-me-with-a-first-time-Splunk/m-p/152012#M30935</guid>
      <dc:creator>batsona</dc:creator>
      <dc:date>2014-12-16T19:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: What tips or documentation can help me with a first time Splunk setup of three different types of syslog coming in: Firewall, Windows and Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-tips-or-documentation-can-help-me-with-a-first-time-Splunk/m-p/152013#M30936</link>
      <description>&lt;P&gt;1) I use syslog as the source type.   I use &lt;STRONG&gt;host_regex&lt;/STRONG&gt; in the inputs to properly set the host name, all the logs have the server name included.  I use a transform to add a friendly log name base of the source, not necessary bu some of my user find this handy.&lt;/P&gt;

&lt;P&gt;2) You want to manage your buckets to move data. I use volumes to keep relevant data on fast disk and aged data goes to slow disk.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Configureindexstoragesize"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Configureindexstoragesize&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;3) You want to make sure you have the right search mode selected,  fast is your friend.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Search/Changethesearchmode"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Search/Changethesearchmode&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2015 18:12:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-tips-or-documentation-can-help-me-with-a-first-time-Splunk/m-p/152013#M30936</guid>
      <dc:creator>trsavela</dc:creator>
      <dc:date>2015-01-21T18:12:45Z</dc:date>
    </item>
  </channel>
</rss>

