<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188962#M37673</link>
    <description>&lt;P&gt;How true! My fears are two-fold: 1) I'm indexing data that's not needed to shine light upon connections/patterns/etc and 2) I'd be excluding events/field values that I think aren't important, but actually are&lt;/P&gt;

&lt;P&gt;Considering using Hadoop on the backend to send all data to and then Hunk to search against the entire data set, but int he meantime re: using Splunk for real-time, proactive alerting I'd like to index only those relevant events/field values &lt;/P&gt;</description>
    <pubDate>Fri, 31 Oct 2014 15:04:30 GMT</pubDate>
    <dc:creator>jwalzerpitt</dc:creator>
    <dc:date>2014-10-31T15:04:30Z</dc:date>
    <item>
      <title>Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188946#M37657</link>
      <description>&lt;P&gt;We use the nxlog agent on out Windows domain controllers/Exchange servers/IIS servers and forward to a centralized rsyslog server. &lt;/P&gt;

&lt;P&gt;Would it be possible to install the Splunk Forwarder on the centralized rsyslog server and filter the syslogs that would be forwarded from the centralized rsyslog server to our Splunk indexer to help filter out the unwanted events?&lt;/P&gt;

&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Wed, 29 Oct 2014 20:51:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188946#M37657</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2014-10-29T20:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188947#M37658</link>
      <description>&lt;P&gt;Yeah, provided you use a heavy forwarder instead of a universal forwarder.&lt;/P&gt;

&lt;P&gt;Note, you can have your indexer(s) filter data regardless of where it came from.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Oct 2014 21:19:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188947#M37658</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-10-29T21:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188948#M37659</link>
      <description>&lt;P&gt;Absolutely! We have a similar setup for the HA with heart beat setup. Like martin said, Heavy Forwarder only.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 00:25:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188948#M37659</guid>
      <dc:creator>Raghav2384</dc:creator>
      <dc:date>2014-10-30T00:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188949#M37660</link>
      <description>&lt;P&gt;Thx for the reply Martin&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 12:40:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188949#M37660</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2014-10-30T12:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188950#M37661</link>
      <description>&lt;P&gt;Thx for the reply&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 12:40:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188950#M37661</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2014-10-30T12:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188951#M37662</link>
      <description>&lt;P&gt;Martin,&lt;/P&gt;

&lt;P&gt;I assume for the rsyslog configuration, it's ok to log to a file, in which I would then configure the forwarded to forward the rsyslog log files to the Indexer, correct?&lt;/P&gt;

&lt;P&gt;Thx again&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 15:16:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188951#M37662</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2014-10-30T15:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188952#M37663</link>
      <description>&lt;P&gt;Yup, having stuff written to a log file and then read by a forwarder with a regular &lt;CODE&gt;monitor://&lt;/CODE&gt; stanza is good practice.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 15:18:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188952#M37663</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-10-30T15:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188953#M37664</link>
      <description>&lt;P&gt;Thx again &lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 15:44:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188953#M37664</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2014-10-30T15:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188954#M37665</link>
      <description>&lt;P&gt;Another one more question &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Is it possible to set the forwarder to be a black list and exclude events/logs that I don't want to be indexed, or does it only function as a white list?&lt;/P&gt;

&lt;P&gt;Thx again&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2014 14:26:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188954#M37665</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2014-10-31T14:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188955#M37666</link>
      <description>&lt;P&gt;I don't quite grasp that sentence, could you elaborate on what you're trying to do?&lt;/P&gt;

&lt;P&gt;There's white/blacklisting on files in inputs.conf, filtering events on heavy forwarders, filtering events on indexers, routing entire files on either, ...&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2014 14:49:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188955#M37666</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-10-31T14:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188956#M37667</link>
      <description>&lt;P&gt;Yes,HF,filter using props &amp;amp; transform,send the ones you do not want to nullqueue. Again, like Martin mentioned below..&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2014 14:53:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188956#M37667</guid>
      <dc:creator>Raghav2384</dc:creator>
      <dc:date>2014-10-31T14:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188957#M37668</link>
      <description>&lt;P&gt;I believe you have answered my poorly worded question. What I mean by blacklisting is say for example I want to prevent Windows Event ID 545 from being indexed, can I create a monitor:// stanza that excludes or prevents Windows Event ID 545 from being indexed? &lt;/P&gt;

&lt;P&gt;My fear was that I'd have to create monitor:// stanza for events I wanted to be indexed, but you stated there is blacklisting via filtering events so it appears I can filter out unneeded events so they don't get indexed.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2014 14:55:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188957#M37668</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2014-10-31T14:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188958#M37669</link>
      <description>&lt;P&gt;Thx for the reply and info.&lt;/P&gt;

&lt;P&gt;At some point I hope they migrate the filtering function onto the Indexer so one can start by indexing everything at first, and then allow the user the ability to go in and start selecting events to be excluded. Not sure how this would effect scalability/performance of the indexer though if it was implemented as such. &lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2014 14:58:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188958#M37669</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2014-10-31T14:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188959#M37670</link>
      <description>&lt;P&gt;For filtering events based on field values you should take a look at the TRANSFORMS-foo entries in props.conf together with transforms.conf. Here's an example: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Routeandfilterdatad"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;That can be done on a Heavy Forwarder xor an Indexer.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2014 14:59:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188959#M37670</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-10-31T14:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188960#M37671</link>
      <description>&lt;P&gt;That's there already, it's called "searching" &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2014 15:00:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188960#M37671</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-10-31T15:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188961#M37672</link>
      <description>&lt;P&gt;Awesome - thx Martin!&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2014 15:01:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188961#M37672</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2014-10-31T15:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188962#M37673</link>
      <description>&lt;P&gt;How true! My fears are two-fold: 1) I'm indexing data that's not needed to shine light upon connections/patterns/etc and 2) I'd be excluding events/field values that I think aren't important, but actually are&lt;/P&gt;

&lt;P&gt;Considering using Hadoop on the backend to send all data to and then Hunk to search against the entire data set, but int he meantime re: using Splunk for real-time, proactive alerting I'd like to index only those relevant events/field values &lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2014 15:04:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188962#M37673</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2014-10-31T15:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to install a Splunk forwarder on centralized rsyslog server to filter out unwanted events before forwarding data to our indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188963#M37674</link>
      <description>&lt;P&gt;Martin,&lt;/P&gt;

&lt;P&gt;I wanted to expand on this question to pick your brain a little more and run through a scenario. We are planning to consume firewall syslog and we log at debugging level, which as you know, is very chatty. With that, if we have the indexer set as a listener, can we filter using transforms on the indexer, or would the firewall syslog need to go to a forwarder first to have events filtered before the data is indexed?&lt;/P&gt;

&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2014 14:52:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-install-a-Splunk-forwarder-on-centralized/m-p/188963#M37674</guid>
      <dc:creator>jwalzerpitt</dc:creator>
      <dc:date>2014-11-07T14:52:39Z</dc:date>
    </item>
  </channel>
</rss>

