<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to send JSON data (sent via HTTP POST) to a heavy forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301070#M56920</link>
    <description>&lt;P&gt;Thank you for the instructions.  When I checked we had that already setup outputs.conf like that.  &lt;/P&gt;

&lt;P&gt;I am currently trying to find out where we went wrong but as I move thru the flow I will find it and post the resolution.&lt;/P&gt;

&lt;P&gt;Currently the security appliance acts as a server to the heavy fwder, and we don't need inputs.conf because the appliance sends host, sourcetype, index, time.   I think we just mis-configured where we assigned the index to...  but still looking&lt;/P&gt;</description>
    <pubDate>Mon, 10 Apr 2017 14:12:28 GMT</pubDate>
    <dc:creator>packet_hunter</dc:creator>
    <dc:date>2017-04-10T14:12:28Z</dc:date>
    <item>
      <title>How to send JSON data (sent via HTTP POST) to a heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301062#M56912</link>
      <description>&lt;P&gt;Currently I have a security appliance sending JSON data via HTTP POST to an all-in-one stand alone Splunk test instance.&lt;BR /&gt;
Now I want to send the JSON data to an intermediate Heavy Forwarder in production (which feeds the indexers).&lt;/P&gt;

&lt;P&gt;The test instance is receiving the json data via HTTP POST.   A Splunk user account was created to pass the RESTful API data with a RESTfulAPI role and edit_tcp capabilities.    The security appliance is configured with the username and password created previously, and is sending data to: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&lt;A href="https://&amp;lt;SplunkAD.DR.ESS&amp;gt;:&amp;lt;PORT&amp;gt;/services/receivers/simple" target="test_blank"&gt;https://&amp;lt;SplunkAD.DR.ESS&amp;gt;:&amp;lt;PORT&amp;gt;/services/receivers/simple&lt;/A&gt;? host=&amp;lt;SecurityApplianceAddress&amp;gt;&amp;amp;source=wmps sourcetype=fe_json
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The stand alone test instance has an enabled receiver directly on the indexer (I believe) and receives the data without a problem.&lt;/P&gt;

&lt;P&gt;At this point I need to reconfigure the security appliance to send data to the heavy fwdr and I am not sure how to set up a receiver on the heavy forwarder so that it will act the same as the test instance.   After the connection is established I would like to edit down the amount of data from the security appliance to only the desired fields by changing the .conf files.&lt;/P&gt;

&lt;P&gt;Any advice or reference is appreciated.&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 16:32:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301062#M56912</guid>
      <dc:creator>packet_hunter</dc:creator>
      <dc:date>2017-04-03T16:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to send JSON data (sent via HTTP POST) to a heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301063#M56913</link>
      <description>&lt;P&gt;You can click on the gear icon in the upper-right of your question and re-edit it.  Even with your clarification, I am certain that I do not understand what you need.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 19:20:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301063#M56913</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-04-03T19:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to send JSON data (sent via HTTP POST) to a heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301064#M56914</link>
      <description>&lt;P&gt;ok here is another attempt to explain, I hope it makes sense&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 19:45:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301064#M56914</guid>
      <dc:creator>packet_hunter</dc:creator>
      <dc:date>2017-04-03T19:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to send JSON data (sent via HTTP POST) to a heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301065#M56915</link>
      <description>&lt;P&gt;MUCH better!  Now I know that I am not the right guy to help but now the right guy will know that he is!&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2017 00:02:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301065#M56915</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-04-04T00:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to send JSON data (sent via HTTP POST) to a heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301066#M56916</link>
      <description>&lt;P&gt;sorry about all my noob confusion&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2017 00:13:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301066#M56916</guid>
      <dc:creator>packet_hunter</dc:creator>
      <dc:date>2017-04-04T00:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to send JSON data (sent via HTTP POST) to a heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301067#M56917</link>
      <description>&lt;P&gt;You can use same method, as you were doing with single test instance&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/226482/splunk-rest-api-data-input-receiverssimple-informa.html"&gt;https://answers.splunk.com/answers/226482/splunk-rest-api-data-input-receiverssimple-informa.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In case you can modify header of the HTTP Post, you can also have a look at HTTP Event Collector.&lt;BR /&gt;
&lt;A href="http://dev.splunk.com/view/event-collector/SP-CAAAE73#scen1"&gt;http://dev.splunk.com/view/event-collector/SP-CAAAE73#scen1&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2017 07:31:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301067#M56917</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2017-04-04T07:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to send JSON data (sent via HTTP POST) to a heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301068#M56918</link>
      <description>&lt;P&gt;Thank you for the reply, I got the security appliance to send to the heavy forwarder, but now I need a inputs.conf to send it to the indexers.&lt;BR /&gt;&lt;BR /&gt;
Any advice on sending this to the indexer is greatly appreciated.&lt;BR /&gt;
Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 19:37:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301068#M56918</guid>
      <dc:creator>packet_hunter</dc:creator>
      <dc:date>2017-04-06T19:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to send JSON data (sent via HTTP POST) to a heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301069#M56919</link>
      <description>&lt;P&gt;To have your heavy forwarder send to the indexers without taking a double license hit, make sure that you set &lt;CODE&gt;outputs.conf&lt;/CODE&gt; (not &lt;CODE&gt;inputs.conf&lt;/CODE&gt;) like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup=YourIndexerGroupHere
indexAndForward=false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.5.1612/Forwarding/Configureforwarderswithoutputs.conf"&gt;http://docs.splunk.com/Documentation/SplunkCloud/6.5.1612/Forwarding/Configureforwarderswithoutputs.conf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Apr 2017 18:40:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301069#M56919</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-04-08T18:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to send JSON data (sent via HTTP POST) to a heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301070#M56920</link>
      <description>&lt;P&gt;Thank you for the instructions.  When I checked we had that already setup outputs.conf like that.  &lt;/P&gt;

&lt;P&gt;I am currently trying to find out where we went wrong but as I move thru the flow I will find it and post the resolution.&lt;/P&gt;

&lt;P&gt;Currently the security appliance acts as a server to the heavy fwder, and we don't need inputs.conf because the appliance sends host, sourcetype, index, time.   I think we just mis-configured where we assigned the index to...  but still looking&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 14:12:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-JSON-data-sent-via-HTTP-POST-to-a-heavy-forwarder/m-p/301070#M56920</guid>
      <dc:creator>packet_hunter</dc:creator>
      <dc:date>2017-04-10T14:12:28Z</dc:date>
    </item>
  </channel>
</rss>

