<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can i have splunk forward data to an external system? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-i-have-splunk-forward-data-to-an-external-system/m-p/9380#M63</link>
    <description>&lt;P&gt;Is it possible to have splunk forward data to another 3rd party system that is expecting syslog?&lt;/P&gt;</description>
    <pubDate>Thu, 21 Jan 2010 09:59:21 GMT</pubDate>
    <dc:creator>Erik_Swan</dc:creator>
    <dc:date>2010-01-21T09:59:21Z</dc:date>
    <item>
      <title>Can i have splunk forward data to an external system?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-i-have-splunk-forward-data-to-an-external-system/m-p/9380#M63</link>
      <description>&lt;P&gt;Is it possible to have splunk forward data to another 3rd party system that is expecting syslog?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2010 09:59:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-i-have-splunk-forward-data-to-an-external-system/m-p/9380#M63</guid>
      <dc:creator>Erik_Swan</dc:creator>
      <dc:date>2010-01-21T09:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can i have splunk forward data to an external system?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-i-have-splunk-forward-data-to-an-external-system/m-p/9381#M64</link>
      <description>&lt;P&gt;Yes,&lt;/P&gt;

&lt;P&gt;Splunk can forward any RFC 3164 compliant events from any platform to a TCP/UDP based server and port, making the payload of any non-compliant data RFC 3164 compliant. You can specify any of the following:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;TCP priority (combination of facility and severity)&lt;/LI&gt;
&lt;LI&gt;Ability to specify regex and forward only the data that matches regex via props/transforms&lt;/LI&gt;
&lt;LI&gt;Filter what is sent by source type, or other meta data, again via props/transforms.&lt;/LI&gt;
&lt;LI&gt;Mandatory truncating of data to 1024 (to comply with RFC 3164)&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;For more info, see:
&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Forwarddatatothird-partysystemsd" rel="nofollow"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Forwarddatatothird-partysystemsd&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2010 10:06:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-i-have-splunk-forward-data-to-an-external-system/m-p/9381#M64</guid>
      <dc:creator>Erik_Swan</dc:creator>
      <dc:date>2010-01-21T10:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: Can i have splunk forward data to an external system?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-i-have-splunk-forward-data-to-an-external-system/m-p/9382#M65</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;If I forward the syslog to 3rd party system will I be able to keep the same info in my internal instance of Splunk as well?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 15:17:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-i-have-splunk-forward-data-to-an-external-system/m-p/9382#M65</guid>
      <dc:creator>dmenon84</dc:creator>
      <dc:date>2016-09-26T15:17:18Z</dc:date>
    </item>
  </channel>
</rss>

