<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using syslog to forward data or Universal forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Using-syslog-to-forward-data-or-Universal-forwarder/m-p/194909#M38781</link>
    <description>&lt;P&gt;I have setup splunk 6.1.1. In our environment we are running rsyslog in a failover configuration.&lt;BR /&gt;
Rsyslog is collecting all the data and then forwarding the data to Splunk. Splunk is configured&lt;BR /&gt;
with a tcp receiver on port 514.  The one issue we are running into is we are getting a large number&lt;BR /&gt;
of entries that are not syslog compliant. We are then getting hosts with names such as 2014,14z etc.&lt;BR /&gt;
I am looking for advice on what would be the best way to reduce these errors? Would the universal forwarder work better at detecting log types and then forwarding it to Splunk?&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jun 2014 18:51:48 GMT</pubDate>
    <dc:creator>andywt123</dc:creator>
    <dc:date>2014-06-10T18:51:48Z</dc:date>
    <item>
      <title>Using syslog to forward data or Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-syslog-to-forward-data-or-Universal-forwarder/m-p/194909#M38781</link>
      <description>&lt;P&gt;I have setup splunk 6.1.1. In our environment we are running rsyslog in a failover configuration.&lt;BR /&gt;
Rsyslog is collecting all the data and then forwarding the data to Splunk. Splunk is configured&lt;BR /&gt;
with a tcp receiver on port 514.  The one issue we are running into is we are getting a large number&lt;BR /&gt;
of entries that are not syslog compliant. We are then getting hosts with names such as 2014,14z etc.&lt;BR /&gt;
I am looking for advice on what would be the best way to reduce these errors? Would the universal forwarder work better at detecting log types and then forwarding it to Splunk?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2014 18:51:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-syslog-to-forward-data-or-Universal-forwarder/m-p/194909#M38781</guid>
      <dc:creator>andywt123</dc:creator>
      <dc:date>2014-06-10T18:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Using syslog to forward data or Universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-syslog-to-forward-data-or-Universal-forwarder/m-p/194910#M38782</link>
      <description>&lt;P&gt;Depending on what information / insights you're looking for, there might be certain info needed from forwarders, in order to put the right data in the right indexes to make the Apps work as designed.&lt;BR /&gt;
SplunkForwarder can collect metrics / stats from Windows, Linux, etc. that are often not easily attainable via syslog (See &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/Aboutforwardingandreceivingdata"&gt;About forwarding and receiving&lt;/A&gt;).&lt;/P&gt;

&lt;P&gt;How many syslog sources are you sending through your rsyslog, and what OS are they?&lt;BR /&gt;
If you aren't sure how to track any possible trends related to where the malformed log entries, then &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Updating/Aboutdeploymentserver"&gt;setting up Deployment&lt;/A&gt; and installing forwarders instead of syslog could definitely help you clean up your data (format errors), as well as provide additional data to bring the apps to life.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Dec 2014 05:00:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-syslog-to-forward-data-or-Universal-forwarder/m-p/194910#M38782</guid>
      <dc:creator>bcdady</dc:creator>
      <dc:date>2014-12-18T05:00:32Z</dc:date>
    </item>
  </channel>
</rss>

