<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can a Heavy Forwarder send cooked but unparsed data? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339872#M62708</link>
    <description>&lt;P&gt;Thanks Koshyk, but that didn't answer the question. I want the Heavy Forwarded to send unparsed cooked data to the indexers. You addressed sending raw and parsed.&lt;/P&gt;</description>
    <pubDate>Sat, 04 Mar 2017 02:44:36 GMT</pubDate>
    <dc:creator>lbur</dc:creator>
    <dc:date>2017-03-04T02:44:36Z</dc:date>
    <item>
      <title>Can a Heavy Forwarder send cooked but unparsed data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339869#M62705</link>
      <description>&lt;P&gt;Is it possible to have a heavy forwarder send unparsed (not raw) cooked data?&lt;BR /&gt;
I have a server which needs to forward data, and a universal forwarder sending compressed, unparsed data would be fine.&lt;BR /&gt;
However, I would like to use that same server to do some data collection as well.&lt;BR /&gt;
This data collection requires a full Splunk install and a 3rd party app (estreamer to be specific).&lt;BR /&gt;
However, as I understanding it using a full Splunk install as a heavy forwarder will, by default send parsed data.&lt;BR /&gt;
This is a much heavier network load, which I would like to avoid.&lt;BR /&gt;
The only option in outputs.conf related to this is: sendCookedData = true | false.&lt;BR /&gt;
If I set this to false, then it will be sending raw (uncooked data to the forwarder).&lt;BR /&gt;
If I set this to true, then it appears the heavy forwarder will send all data as cooked, &lt;STRONG&gt;parsed&lt;/STRONG&gt; data.&lt;BR /&gt;
I'm looking for an option to send cooked, &lt;STRONG&gt;unparsed&lt;/STRONG&gt; data.&lt;/P&gt;

&lt;P&gt;Thanks for any help!&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2017 21:54:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339869#M62705</guid>
      <dc:creator>lbur</dc:creator>
      <dc:date>2017-03-03T21:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: Can a Heavy Forwarder send cooked but unparsed data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339870#M62706</link>
      <description>&lt;P&gt;You could have ANY number of outputs to any locations. So you send outputs to "Destination1 - Third Party" which is not cooked, but to "destination2 - xyz" which is cooked etc.  Each tcpout stanza can vary depending on how you want it.&lt;BR /&gt;
( by-the-way estreamer is a pain !!  and I won't go near it as it is unsupported)&lt;/P&gt;

&lt;P&gt;Also the heavy-forwarder gives option for OUTPUT in syslog format which is great to way to make Splunk work as a logging engine to centralised logging solutions.  In one of the customers, we collect using Splunk UF from various machines and at Heavy-forwarder we dump to syslog server for multiple other third parties. We don't want to integrate , but rather we dump into central location in uncooked format and it is up-to the company/third-party how they take it.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2017 23:24:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339870#M62706</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2017-03-03T23:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Can a Heavy Forwarder send cooked but unparsed data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339871#M62707</link>
      <description>&lt;P&gt;Thanks Koshyk, but that didn't answer the question. I want the Heavy Forwarded to send &lt;STRONG&gt;unparsed&lt;/STRONG&gt; cooked data to the indexers.  You addressed sending raw and &lt;STRONG&gt;parsed&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Mar 2017 02:43:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339871#M62707</guid>
      <dc:creator>lbur</dc:creator>
      <dc:date>2017-03-04T02:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: Can a Heavy Forwarder send cooked but unparsed data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339872#M62708</link>
      <description>&lt;P&gt;Thanks Koshyk, but that didn't answer the question. I want the Heavy Forwarded to send unparsed cooked data to the indexers. You addressed sending raw and parsed.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Mar 2017 02:44:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339872#M62708</guid>
      <dc:creator>lbur</dc:creator>
      <dc:date>2017-03-04T02:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can a Heavy Forwarder send cooked but unparsed data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339873#M62709</link>
      <description>&lt;P&gt;I'm assuming you want to send from UF to a full Splunk installation.&lt;BR /&gt;
If you look into the &lt;A href="https://wiki.splunk.com/Community:HowIndexingWorks"&gt;indexing piplelines&lt;/A&gt; , the UF does NOT do the real parsing (Detail Diagram - UF/LWF to Indexer). So the output from from ur UF will be "cooked but unparsed data"&lt;/P&gt;</description>
      <pubDate>Sat, 04 Mar 2017 07:38:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339873#M62709</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2017-03-04T07:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: Can a Heavy Forwarder send cooked but unparsed data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339874#M62710</link>
      <description>&lt;P&gt;No, I want to send from a Heavy Forwarder (because I need the full Splunk Installation for other purposes, like estreamer and dbconnect), but for normal file monitor functions (for instance) I want to forward cooked, &lt;STRONG&gt;unparsed&lt;/STRONG&gt; data, in order to limit the network bandwidth.  However, it seems as if the Heavy Forwarder can only be configured to send either raw,  or cooked &lt;STRONG&gt;parsed&lt;/STRONG&gt; data, which is much larger than unparsed data.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Mar 2017 15:05:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339874#M62710</guid>
      <dc:creator>lbur</dc:creator>
      <dc:date>2017-03-04T15:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Can a Heavy Forwarder send cooked but unparsed data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339875#M62711</link>
      <description>&lt;P&gt;One option would to have both Splunk Enterprise Instance and a Universal Forwarder on your machine generating data. Use Heavy forwarder only for estreamer specific monitoring and UF for rest. (you can't turn off parsing on HF, you may configure it to be reparsed at indexers).&lt;/P&gt;</description>
      <pubDate>Sat, 04 Mar 2017 17:14:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339875#M62711</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-03-04T17:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can a Heavy Forwarder send cooked but unparsed data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339876#M62712</link>
      <description>&lt;P&gt;Hi lbur, I'm having the same problem. Trying to send cooked and unparsed data from a Heavy Forwarder, so we don't have to re-distribute or re-plan data collection/ingestion, and I'm trying to avoid any additional configuration on the indexers' queues.&lt;/P&gt;

&lt;P&gt;Have you gotten anywhere with this?&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2018 09:48:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339876#M62712</guid>
      <dc:creator>danielhernandez</dc:creator>
      <dc:date>2018-05-14T09:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can a Heavy Forwarder send cooked but unparsed data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339877#M62713</link>
      <description>&lt;P&gt;Hi folks. The easiest way to minimize network bandwidth impact from a HF is to: &lt;BR /&gt;
1. Use the HF to monitor/interface with only the data sources that you need the HF for. I assume you want the HF for the UI needs, but some apps might use the parsing. This is what @somesoni2 is recommending.&lt;BR /&gt;
2. Send the cooked, parsed output to the indexers via SSL, leveraging the SSL compression. This dramatically lowers the network impact, in exchange for admin overhead of setup and configuration.&lt;/P&gt;</description>
      <pubDate>Mon, 14 May 2018 16:39:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/339877#M62713</guid>
      <dc:creator>ekost</dc:creator>
      <dc:date>2018-05-14T16:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can a Heavy Forwarder send cooked but unparsed data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/630550#M108075</link>
      <description>&lt;P&gt;I realize this is a very old post, but as I was browsing I didn't see an answer to your questions.&amp;nbsp; The best answer is probably to use a LightweightForwarders.&amp;nbsp; Yes, I know it's supposedly deprecated, but it does pretty much what you want.&amp;nbsp; That is, it sends cooked, but unparsed/unindexed data to the indexer.&amp;nbsp; It also gives you all of the functionality such as Python, HEC inputs, etc.&amp;nbsp; By default, the LightweightForwarder will disable the web interface, but that can be turned though the web.conf setting.&amp;nbsp; I use this configuration in my DMZ.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2023 19:57:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-a-Heavy-Forwarder-send-cooked-but-unparsed-data/m-p/630550#M108075</guid>
      <dc:creator>dokaas_2</dc:creator>
      <dc:date>2023-02-11T19:57:00Z</dc:date>
    </item>
  </channel>
</rss>

