<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can someone explain splunk overview for data forwarding and parsing? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-explain-splunk-overview-for-data-forwarding-and/m-p/247384#M47708</link>
    <description>&lt;P&gt;I just want to know the overall flow start from uf to indexer with example so that i get a clear idea ,i am stuck near the conf files and how the data from log files is connected&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jan 2016 23:22:15 GMT</pubDate>
    <dc:creator>chaseto</dc:creator>
    <dc:date>2016-01-25T23:22:15Z</dc:date>
    <item>
      <title>Can someone explain splunk overview for data forwarding and parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-explain-splunk-overview-for-data-forwarding-and/m-p/247382#M47706</link>
      <description>&lt;P&gt;Hello Experts,&lt;BR /&gt;
I am new to splunk and learning it.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/Routeandfilterdatad"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I have read the above  document in splunk  regarding routing and filtering of data ,Can someone please explain with an example in detail how the parsing,filtering and configure routing(configuration files) is done if possible..&lt;/P&gt;

&lt;P&gt;Thanks in advanace&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2016 22:33:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-explain-splunk-overview-for-data-forwarding-and/m-p/247382#M47706</guid>
      <dc:creator>chaseto</dc:creator>
      <dc:date>2016-01-25T22:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone explain splunk overview for data forwarding and parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-explain-splunk-overview-for-data-forwarding-and/m-p/247383#M47707</link>
      <description>&lt;P&gt;Hi chaseto, could you please explain a bit more what is not clear to you? Because the docs you linked include examples and detailed steps how to configure parsing, filtering ( &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/Routeandfilterdatad#Filter_and_route_event_data_to_target_groups"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/Routeandfilterdatad#Filter_and_route_event_data_to_target_groups&lt;/A&gt; ) and routing ( &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/Routeandfilterdatad#Configure_routing"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/Routeandfilterdatad#Configure_routing&lt;/A&gt; )&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2016 23:05:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-explain-splunk-overview-for-data-forwarding-and/m-p/247383#M47707</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2016-01-25T23:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone explain splunk overview for data forwarding and parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-explain-splunk-overview-for-data-forwarding-and/m-p/247384#M47708</link>
      <description>&lt;P&gt;I just want to know the overall flow start from uf to indexer with example so that i get a clear idea ,i am stuck near the conf files and how the data from log files is connected&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2016 23:22:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-explain-splunk-overview-for-data-forwarding-and/m-p/247384#M47708</guid>
      <dc:creator>chaseto</dc:creator>
      <dc:date>2016-01-25T23:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone explain splunk overview for data forwarding and parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-explain-splunk-overview-for-data-forwarding-and/m-p/247385#M47709</link>
      <description>&lt;P&gt;On the UF you did set a &lt;CODE&gt;sourcetype&lt;/CODE&gt; for the log in &lt;CODE&gt;inputs.conf&lt;/CODE&gt; - did you? Use this sourcetype in your &lt;CODE&gt;props.conf&lt;/CODE&gt; on the indexer and reference a stanza from &lt;CODE&gt;transforms.conf&lt;/CODE&gt; , as well on the indexer. Restart Splunk after the changes to the conf files and any new data flowing in should be filtered and routed. If not provide all conf files please.&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2016 23:26:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-explain-splunk-overview-for-data-forwarding-and/m-p/247385#M47709</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2016-01-25T23:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone explain splunk overview for data forwarding and parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-explain-splunk-overview-for-data-forwarding-and/m-p/247386#M47710</link>
      <description>&lt;P&gt;thanks Mus&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2016 23:34:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-explain-splunk-overview-for-data-forwarding-and/m-p/247386#M47710</guid>
      <dc:creator>chaseto</dc:creator>
      <dc:date>2016-01-25T23:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone explain splunk overview for data forwarding and parsing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-someone-explain-splunk-overview-for-data-forwarding-and/m-p/247387#M47711</link>
      <description>&lt;P&gt;hello chaseto&lt;BR /&gt;
here already somebody given the answer for it.so check it once.it may useful for you&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/352888/how-to-configure-the-splunk-universal-forwarder-an.html"&gt;https://answers.splunk.com/answers/352888/how-to-configure-the-splunk-universal-forwarder-an.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2016 07:42:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-someone-explain-splunk-overview-for-data-forwarding-and/m-p/247387#M47711</guid>
      <dc:creator>Umesh_Vedicsoft</dc:creator>
      <dc:date>2016-02-02T07:42:32Z</dc:date>
    </item>
  </channel>
</rss>

