<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can audit.log be forwarded to another index? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-audit-log-be-forwarded-to-another-index/m-p/280016#M53601</link>
    <description>&lt;P&gt;Not sure, but, Just a thought, the audit, splunkd logs may be already indexed thru splunk's own internal indexes, isn't ?!?! &lt;/P&gt;</description>
    <pubDate>Wed, 11 Jan 2017 19:15:20 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2017-01-11T19:15:20Z</dc:date>
    <item>
      <title>Can audit.log be forwarded to another index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-audit-log-be-forwarded-to-another-index/m-p/280014#M53599</link>
      <description>&lt;P&gt;Hello There&lt;/P&gt;

&lt;P&gt;I'm trying to index a few Splunk internal logs like splunkd, metrics, web*, audit, etc under /var/log/splunk to another index, however, all the logs are populating in the other index except audit.log&lt;/P&gt;

&lt;P&gt;please suggest..&lt;/P&gt;

&lt;P&gt;Many Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2016 07:12:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-audit-log-be-forwarded-to-another-index/m-p/280014#M53599</guid>
      <dc:creator>nmouli</dc:creator>
      <dc:date>2016-06-03T07:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can audit.log be forwarded to another index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-audit-log-be-forwarded-to-another-index/m-p/280015#M53600</link>
      <description>&lt;P&gt;I have changed the audit log location in log.cfg (log-local.cfg) to other directory and then able to index it.&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2017 18:52:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-audit-log-be-forwarded-to-another-index/m-p/280015#M53600</guid>
      <dc:creator>nmouli</dc:creator>
      <dc:date>2017-01-11T18:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can audit.log be forwarded to another index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-audit-log-be-forwarded-to-another-index/m-p/280016#M53601</link>
      <description>&lt;P&gt;Not sure, but, Just a thought, the audit, splunkd logs may be already indexed thru splunk's own internal indexes, isn't ?!?! &lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2017 19:15:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-audit-log-be-forwarded-to-another-index/m-p/280016#M53601</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-01-11T19:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: Can audit.log be forwarded to another index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-audit-log-be-forwarded-to-another-index/m-p/280017#M53602</link>
      <description>&lt;P&gt;Yes, however I'd like to send many UF internal logs to other existing index rather than Splunk own internal index to develop a customized app.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2017 19:29:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-audit-log-be-forwarded-to-another-index/m-p/280017#M53602</guid>
      <dc:creator>nmouli</dc:creator>
      <dc:date>2017-01-11T19:29:39Z</dc:date>
    </item>
  </channel>
</rss>

