<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Archive raw and/or indexed data to external syslog server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Archive-raw-and-or-indexed-data-to-external-syslog-server/m-p/310122#M58271</link>
    <description>&lt;P&gt;Thanks, but we hope to forward to-be-fronzen data to external server (e.g. a syslog server) for archiving.&lt;/P&gt;</description>
    <pubDate>Fri, 20 Oct 2017 09:44:03 GMT</pubDate>
    <dc:creator>stwong</dc:creator>
    <dc:date>2017-10-20T09:44:03Z</dc:date>
    <item>
      <title>Archive raw and/or indexed data to external syslog server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Archive-raw-and-or-indexed-data-to-external-syslog-server/m-p/310119#M58268</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;Our Splunk server is getting data through several channels, e.g. universal forwarders, TCP input (e.g. OPSEC LEA of Checkpoint data),  SNMP, DB connection, etc.).   We hope to make a copy of these data (either raw or indexed) to external server (e.g. syslog) for long term archiving.&lt;BR /&gt;
We're looking for any recommended solution.   Would anyone please help?&lt;/P&gt;

&lt;P&gt;Thanks a lot.&lt;BR /&gt;
Rgds&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 02:34:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Archive-raw-and-or-indexed-data-to-external-syslog-server/m-p/310119#M58268</guid>
      <dc:creator>stwong</dc:creator>
      <dc:date>2017-10-18T02:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Archive raw and/or indexed data to external syslog server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Archive-raw-and-or-indexed-data-to-external-syslog-server/m-p/310120#M58269</link>
      <description>&lt;P&gt;I think that you can backup and save it on a file server etc.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Backupindexeddata"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Backupindexeddata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 04:28:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Archive-raw-and-or-indexed-data-to-external-syslog-server/m-p/310120#M58269</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2017-10-18T04:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: Archive raw and/or indexed data to external syslog server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Archive-raw-and-or-indexed-data-to-external-syslog-server/m-p/310121#M58270</link>
      <description>&lt;P&gt;Hi stwong,&lt;/P&gt;

&lt;P&gt;you can easily use Splunk for long term archiving ( see &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Setaretirementandarchivingpolicy"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Setaretirementandarchivingpolicy&lt;/A&gt; ) you don't need to use an external system.&lt;/P&gt;

&lt;P&gt;Anyway if you want to use a third party external system, you can forward all logs to an external system using syslogs ( see &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd&lt;/A&gt; ).&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 06:58:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Archive-raw-and-or-indexed-data-to-external-syslog-server/m-p/310121#M58270</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-10-18T06:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: Archive raw and/or indexed data to external syslog server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Archive-raw-and-or-indexed-data-to-external-syslog-server/m-p/310122#M58271</link>
      <description>&lt;P&gt;Thanks, but we hope to forward to-be-fronzen data to external server (e.g. a syslog server) for archiving.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2017 09:44:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Archive-raw-and-or-indexed-data-to-external-syslog-server/m-p/310122#M58271</guid>
      <dc:creator>stwong</dc:creator>
      <dc:date>2017-10-20T09:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: Archive raw and/or indexed data to external syslog server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Archive-raw-and-or-indexed-data-to-external-syslog-server/m-p/310123#M58272</link>
      <description>&lt;P&gt;Thanks,    We've to use indexAndForward=true for forwarding to third party, correct?&lt;/P&gt;

&lt;P&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2017 09:47:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Archive-raw-and-or-indexed-data-to-external-syslog-server/m-p/310123#M58272</guid>
      <dc:creator>stwong</dc:creator>
      <dc:date>2017-10-20T09:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: Archive raw and/or indexed data to external syslog server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Archive-raw-and-or-indexed-data-to-external-syslog-server/m-p/310124#M58273</link>
      <description>&lt;P&gt;Hi stwong,&lt;BR /&gt;
if you're satisfied by this answer, please accept or upvote it.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2017 11:45:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Archive-raw-and-or-indexed-data-to-external-syslog-server/m-p/310124#M58273</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-10-20T11:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Archive raw and/or indexed data to external syslog server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Archive-raw-and-or-indexed-data-to-external-syslog-server/m-p/310125#M58274</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;

&lt;P&gt;Thanks.  Will try it out.&lt;/P&gt;

&lt;P&gt;/STwong&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2017 12:41:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Archive-raw-and-or-indexed-data-to-external-syslog-server/m-p/310125#M58274</guid>
      <dc:creator>stwong</dc:creator>
      <dc:date>2017-10-20T12:41:58Z</dc:date>
    </item>
  </channel>
</rss>

