<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can I replace Splunk Universal Forwarder with Apache NiFi? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-Splunk-Universal-Forwarder-with-Apache-NiFi/m-p/357216#M65229</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;
a little bit late but... &lt;/P&gt;

&lt;P&gt;As far as I understand putSplunk is sending data just using TCP or UDP inputs.&lt;/P&gt;

&lt;P&gt;So... this should do the trick on Splunk UFW side...&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Remember, that if you want to send different type of data please use different ports and define index and sourcetype in your inputs.conf.&lt;/P&gt;

&lt;P&gt;Much better is using Splunk HTTP Event Collector ... &lt;/P&gt;

&lt;P&gt;I think it's "AttributeToJSON" then?&lt;/P&gt;

&lt;P&gt;HTH,&lt;/P&gt;

&lt;P&gt;Holger&lt;/P&gt;</description>
    <pubDate>Sun, 11 Mar 2018 20:06:39 GMT</pubDate>
    <dc:creator>hsesterhenn_spl</dc:creator>
    <dc:date>2018-03-11T20:06:39Z</dc:date>
    <item>
      <title>Can I replace Splunk Universal Forwarder with Apache NiFi?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-Splunk-Universal-Forwarder-with-Apache-NiFi/m-p/357215#M65228</link>
      <description>&lt;P&gt;NiFi has a putSplunk processor that should do what I want (send data to an indexer)&lt;/P&gt;

&lt;P&gt;BUT it doesn't have any place for me to specify sourcetype, or index, and it only has one "Host" field, whereas I usually use autolb with 2 indexers.&lt;/P&gt;

&lt;P&gt;Can I do this? If so, how? &lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2017 19:05:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-Splunk-Universal-Forwarder-with-Apache-NiFi/m-p/357215#M65228</guid>
      <dc:creator>gozulin</dc:creator>
      <dc:date>2017-03-15T19:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Can I replace Splunk Universal Forwarder with Apache NiFi?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-Splunk-Universal-Forwarder-with-Apache-NiFi/m-p/357216#M65229</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
a little bit late but... &lt;/P&gt;

&lt;P&gt;As far as I understand putSplunk is sending data just using TCP or UDP inputs.&lt;/P&gt;

&lt;P&gt;So... this should do the trick on Splunk UFW side...&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Remember, that if you want to send different type of data please use different ports and define index and sourcetype in your inputs.conf.&lt;/P&gt;

&lt;P&gt;Much better is using Splunk HTTP Event Collector ... &lt;/P&gt;

&lt;P&gt;I think it's "AttributeToJSON" then?&lt;/P&gt;

&lt;P&gt;HTH,&lt;/P&gt;

&lt;P&gt;Holger&lt;/P&gt;</description>
      <pubDate>Sun, 11 Mar 2018 20:06:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-replace-Splunk-Universal-Forwarder-with-Apache-NiFi/m-p/357216#M65229</guid>
      <dc:creator>hsesterhenn_spl</dc:creator>
      <dc:date>2018-03-11T20:06:39Z</dc:date>
    </item>
  </channel>
</rss>

