<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP Event Collector: Can I set up a farm of Splunk 6.3 forwarders and send them to to 6.1 indexers? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Can-I-set-up-a-farm-of-Splunk-6-3/m-p/258742#M49674</link>
    <description>&lt;P&gt;Hi folks&lt;/P&gt;

&lt;P&gt;We've just added new documentation on distributed deployment. You can find it &lt;A href="http://dev.splunk.com/view/event-collector/SP-CAAAE73"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Nov 2015 02:03:04 GMT</pubDate>
    <dc:creator>gblock_splunk</dc:creator>
    <dc:date>2015-11-04T02:03:04Z</dc:date>
    <item>
      <title>HTTP Event Collector: Can I set up a farm of Splunk 6.3 forwarders and send them to to 6.1 indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Can-I-set-up-a-farm-of-Splunk-6-3/m-p/258739#M49671</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have customers interested in using the HTTP event collector, but I'm still running 6.1 indexers and search heads.  Can I set up a farm of 6.3 forwarders and send them to 6.1 indexers?  &lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2015 19:38:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Can-I-set-up-a-farm-of-Splunk-6-3/m-p/258739#M49671</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2015-10-05T19:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector: Can I set up a farm of Splunk 6.3 forwarders and send them to to 6.1 indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Can-I-set-up-a-farm-of-Splunk-6-3/m-p/258740#M49672</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/UsetheHTTPEventCollector"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/UsetheHTTPEventCollector&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/admin/Inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/admin/Inputsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I'm not seeing anything that says that the functionality does not exist on [universal] forwarders but haven't tried.  I'd say give it a try and see? You can run a curl command against it to see if it catches your http request.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2015 20:50:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Can-I-set-up-a-farm-of-Splunk-6-3/m-p/258740#M49672</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2015-10-05T20:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector: Can I set up a farm of Splunk 6.3 forwarders and send them to to 6.1 indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Can-I-set-up-a-farm-of-Splunk-6-3/m-p/258741#M49673</link>
      <description>&lt;P&gt;Yes you can have 6.3 Event Collector instances which forward to 6.2. In the configuration of EC you can select an output group for it to forward to. The receiving indexers do not have to be 6.3.&lt;/P&gt;

&lt;P&gt;As to the UF, it is not supported today, though it may work. Only HWF is supported from a forwarder perspective.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2015 10:00:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Can-I-set-up-a-farm-of-Splunk-6-3/m-p/258741#M49673</guid>
      <dc:creator>gblock_splunk</dc:creator>
      <dc:date>2015-10-06T10:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Event Collector: Can I set up a farm of Splunk 6.3 forwarders and send them to to 6.1 indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Can-I-set-up-a-farm-of-Splunk-6-3/m-p/258742#M49674</link>
      <description>&lt;P&gt;Hi folks&lt;/P&gt;

&lt;P&gt;We've just added new documentation on distributed deployment. You can find it &lt;A href="http://dev.splunk.com/view/event-collector/SP-CAAAE73"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 02:03:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HTTP-Event-Collector-Can-I-set-up-a-farm-of-Splunk-6-3/m-p/258742#M49674</guid>
      <dc:creator>gblock_splunk</dc:creator>
      <dc:date>2015-11-04T02:03:04Z</dc:date>
    </item>
  </channel>
</rss>

