<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I forward a particular event ID to another host? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209151#M41191</link>
    <description>&lt;P&gt;This should get you going&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Forwarding/Routeandfilterdatad"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Sep 2015 14:12:29 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2015-09-11T14:12:29Z</dc:date>
    <item>
      <title>How can I forward a particular event ID to another host?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209147#M41187</link>
      <description>&lt;P&gt;I have a scenario where I need to forward a particular event ID to another host. Can I use the universal forwarder for this, or do I need to configure something in Splunk to forward that? I'm a little new to Splunk, but have it up and running on Linux.&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2015 16:33:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209147#M41187</guid>
      <dc:creator>ericsolson</dc:creator>
      <dc:date>2015-09-10T16:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: How can I forward a particular event ID to another host?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209148#M41188</link>
      <description>&lt;P&gt;Are you just trying to forward only a single event ID to one location or are you trying to send everything somewhere and also send one event ID to another location?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 13:58:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209148#M41188</guid>
      <dc:creator>dturnbull_splun</dc:creator>
      <dc:date>2015-09-11T13:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: How can I forward a particular event ID to another host?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209149#M41189</link>
      <description>&lt;P&gt;Everything is going to Splunk from my Windows servers. I need one event ID to go to another separate system that is being monitored in real time :).&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 14:07:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209149#M41189</guid>
      <dc:creator>ericsolson</dc:creator>
      <dc:date>2015-09-11T14:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: How can I forward a particular event ID to another host?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209150#M41190</link>
      <description>&lt;P&gt;How does the other system want the data? &lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 14:12:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209150#M41190</guid>
      <dc:creator>dturnbull_splun</dc:creator>
      <dc:date>2015-09-11T14:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: How can I forward a particular event ID to another host?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209151#M41191</link>
      <description>&lt;P&gt;This should get you going&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Forwarding/Routeandfilterdatad"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.5/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 14:12:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209151#M41191</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-09-11T14:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: How can I forward a particular event ID to another host?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209152#M41192</link>
      <description>&lt;P&gt;Syslog format is fine&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 14:14:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209152#M41192</guid>
      <dc:creator>ericsolson</dc:creator>
      <dc:date>2015-09-11T14:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: How can I forward a particular event ID to another host?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209153#M41193</link>
      <description>&lt;P&gt;You'll want to configure forwarding from your indexers if you want to send to either &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Forwarding/Routeandfilterdatad#Perform_selective_indexing_and_forwarding"&gt;another Splunk system&lt;/A&gt; or as &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.5/Forwarding/Forwarddatatothird-partysystemsd"&gt;TCP or Syslog&lt;/A&gt;. If you need to reformat the data, for example by exporting to ArcSight, you can use the &lt;A href="https://splunkbase.splunk.com/app/1847/"&gt;Splunk App for CEF&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 14:14:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209153#M41193</guid>
      <dc:creator>dturnbull_splun</dc:creator>
      <dc:date>2015-09-11T14:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: How can I forward a particular event ID to another host?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209154#M41194</link>
      <description>&lt;P&gt;Thanks. This event id is going from Splunk to another Windows host with a syslog listener.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2015 14:21:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-forward-a-particular-event-ID-to-another-host/m-p/209154#M41194</guid>
      <dc:creator>ericsolson</dc:creator>
      <dc:date>2015-09-11T14:21:24Z</dc:date>
    </item>
  </channel>
</rss>

