<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can someone delineate the advantages/disadvantages of using the universal forwarder vs. the oneshot command? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225287#M44073</link>
    <description>&lt;P&gt;Then, simply put, use the UF. Then in Splunk, write a saved scheduled report that finds that data. If count &amp;lt; 1, then it didn't make it. If it is count &amp;gt; 0, then you are good to go. &lt;/P&gt;</description>
    <pubDate>Tue, 15 Sep 2015 16:54:55 GMT</pubDate>
    <dc:creator>alacercogitatus</dc:creator>
    <dc:date>2015-09-15T16:54:55Z</dc:date>
    <item>
      <title>Can someone delineate the advantages/disadvantages of using the universal forwarder vs. the oneshot command?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225278#M44064</link>
      <description>&lt;P&gt;My team has been thinking about changing to the Splunk CLI oneshot command instead of the Splunk Universal Forwarder configs and traditional monitoring.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2015 16:00:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225278#M44064</guid>
      <dc:creator>jaredlaney</dc:creator>
      <dc:date>2015-09-15T16:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone delineate the advantages/disadvantages of using the universal forwarder vs. the oneshot command?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225279#M44065</link>
      <description>&lt;P&gt;So you are contemplating recreating all of the functionality that a forwarder provides by coding it yourself and using the &lt;CODE&gt;oneshot&lt;/CODE&gt; command and the method of injecting stuff into Splunk?  WHY????  That is &lt;EM&gt;crazy&lt;/EM&gt;!  I find it difficult to imagine something that you might like to add to a forwarder that you cannot already do using Splunk's own forwarder configuration capabilities.  Are you joking or am I misunderstanding you?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2015 16:09:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225279#M44065</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-09-15T16:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone delineate the advantages/disadvantages of using the universal forwarder vs. the oneshot command?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225280#M44066</link>
      <description>&lt;P&gt;I'm not but I need reasons to convince my team otherwise.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2015 16:20:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225280#M44066</guid>
      <dc:creator>jaredlaney</dc:creator>
      <dc:date>2015-09-15T16:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone delineate the advantages/disadvantages of using the universal forwarder vs. the oneshot command?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225281#M44067</link>
      <description>&lt;P&gt;What else does it provide besides buffering, failover, and a round robin load balance (not a true load balance)? That is what I'm trying to explain to them.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2015 16:24:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225281#M44067</guid>
      <dc:creator>jaredlaney</dc:creator>
      <dc:date>2015-09-15T16:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone delineate the advantages/disadvantages of using the universal forwarder vs. the oneshot command?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225282#M44068</link>
      <description>&lt;P&gt;Let's see: SSL, multiple destinations, buffering, transforming, timezoning, debugging tools, C&amp;amp;C by Deployment Server, Integration into DMC...&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2015 16:30:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225282#M44068</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-09-15T16:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone delineate the advantages/disadvantages of using the universal forwarder vs. the oneshot command?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225283#M44069</link>
      <description>&lt;P&gt;Not to mention Windows event log black/white lists, continuous file monitoring (oneshot would have to be scripted), Windows perfmon/powershell collection natively, etc etc etc.&lt;/P&gt;

&lt;P&gt;@jaredlaney, what problem is your team seeing that caused this change of heart? I bet it can be fixed......&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2015 16:41:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225283#M44069</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2015-09-15T16:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone delineate the advantages/disadvantages of using the universal forwarder vs. the oneshot command?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225284#M44070</link>
      <description>&lt;P&gt;Thanks for the ammunition.  They relented...  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2015 16:44:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225284#M44070</guid>
      <dc:creator>jaredlaney</dc:creator>
      <dc:date>2015-09-15T16:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone delineate the advantages/disadvantages of using the universal forwarder vs. the oneshot command?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225285#M44071</link>
      <description>&lt;P&gt;Our files are static and we don't do Windows but definitely true.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2015 16:45:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225285#M44071</guid>
      <dc:creator>jaredlaney</dc:creator>
      <dc:date>2015-09-15T16:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone delineate the advantages/disadvantages of using the universal forwarder vs. the oneshot command?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225286#M44072</link>
      <description>&lt;P&gt;We have static log files that get created once a day and we're looking for a way to verify that the data made it to Splunk.  We're thinking that we'd have to query Splunk through the Rest interface to verify that the data made it.  &lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2015 16:50:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225286#M44072</guid>
      <dc:creator>jaredlaney</dc:creator>
      <dc:date>2015-09-15T16:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone delineate the advantages/disadvantages of using the universal forwarder vs. the oneshot command?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225287#M44073</link>
      <description>&lt;P&gt;Then, simply put, use the UF. Then in Splunk, write a saved scheduled report that finds that data. If count &amp;lt; 1, then it didn't make it. If it is count &amp;gt; 0, then you are good to go. &lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2015 16:54:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-delineate-the-advantages-disadvantages-of-using-the/m-p/225287#M44073</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2015-09-15T16:54:55Z</dc:date>
    </item>
  </channel>
</rss>

