<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I configure a UF on Linux to receive and forward windows events? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-UF-on-Linux-to-receive-and-forward-windows/m-p/357833#M65353</link>
    <description>&lt;P&gt;And how exactly did you envision that windows server sending the logs to the Linux UF?&lt;/P&gt;

&lt;P&gt;Unless you also put Splunk on the windows box (or use some sub-optimal solution with an agent like Snare) I don't really see how you are going to accomplish that.&lt;/P&gt;

&lt;P&gt;Assuming you have Splunk on the windows box as well and the Linux UF just acts as an intermediate forwarder, it should be as simple as enabling a splunktcp input on the UF and setting the correct output config to send to your indexers.&lt;/P&gt;

&lt;P&gt;What exactly are you not sure about?&lt;/P&gt;</description>
    <pubDate>Tue, 24 Apr 2018 12:58:44 GMT</pubDate>
    <dc:creator>FrankVl</dc:creator>
    <dc:date>2018-04-24T12:58:44Z</dc:date>
    <item>
      <title>How do I configure a UF on Linux to receive and forward windows events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-UF-on-Linux-to-receive-and-forward-windows/m-p/357832#M65352</link>
      <description>&lt;P&gt;I need to configure a Linux based UF to receive Windows events and then forwarder those to the indexers. I am guessing that there is a &lt;BR /&gt;
inputs.conf and outputs.conf needing to be configured.&lt;/P&gt;

&lt;P&gt;Just not sure how to configure these stanza's, mostly inputs.conf.&lt;/P&gt;

&lt;P&gt;This would receive events from windows server in a webzone, so we only need to open the firewall for the UF.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 12:54:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-UF-on-Linux-to-receive-and-forward-windows/m-p/357832#M65352</guid>
      <dc:creator>pfabrizi</dc:creator>
      <dc:date>2018-04-24T12:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a UF on Linux to receive and forward windows events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-UF-on-Linux-to-receive-and-forward-windows/m-p/357833#M65353</link>
      <description>&lt;P&gt;And how exactly did you envision that windows server sending the logs to the Linux UF?&lt;/P&gt;

&lt;P&gt;Unless you also put Splunk on the windows box (or use some sub-optimal solution with an agent like Snare) I don't really see how you are going to accomplish that.&lt;/P&gt;

&lt;P&gt;Assuming you have Splunk on the windows box as well and the Linux UF just acts as an intermediate forwarder, it should be as simple as enabling a splunktcp input on the UF and setting the correct output config to send to your indexers.&lt;/P&gt;

&lt;P&gt;What exactly are you not sure about?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 12:58:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-UF-on-Linux-to-receive-and-forward-windows/m-p/357833#M65353</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-04-24T12:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a UF on Linux to receive and forward windows events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-UF-on-Linux-to-receive-and-forward-windows/m-p/357834#M65354</link>
      <description>&lt;P&gt;I am not sure on how to setup the tcp input, to accept events from 300 windows servers. Windows servers will be running windows SPLUNK UF. &lt;/P&gt;

&lt;P&gt;should the input just look for the Windows UF port?&lt;BR /&gt;&lt;BR /&gt;
Which would be?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 13:33:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-UF-on-Linux-to-receive-and-forward-windows/m-p/357834#M65354</guid>
      <dc:creator>pfabrizi</dc:creator>
      <dc:date>2018-04-24T13:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a UF on Linux to receive and forward windows events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-UF-on-Linux-to-receive-and-forward-windows/m-p/357835#M65355</link>
      <description>&lt;P&gt;Technically you can use whatever port you want. Just as long as the outputs.conf on the windows UFs is using the same port as the splunktcp input (so not a normal TCP input) on your Linux UF intermediate forwarder. In general I guess 9997 is typically used for this.&lt;/P&gt;

&lt;P&gt;See also the documentation on how to set up forwarding (basically this is no different from setting up forwarding from a forwarder to an indexer, just that you have one more splunk instance in between, that receives and then also sends it again).&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Aboutforwardingandreceivingdata"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Aboutforwardingandreceivingdata&lt;/A&gt;&lt;BR /&gt;
specifically: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Configureanintermediateforwarder"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Configureanintermediateforwarder&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 14:06:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-UF-on-Linux-to-receive-and-forward-windows/m-p/357835#M65355</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-04-24T14:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a UF on Linux to receive and forward windows events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-UF-on-Linux-to-receive-and-forward-windows/m-p/357836#M65356</link>
      <description>&lt;P&gt;Thank You!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 14:58:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-UF-on-Linux-to-receive-and-forward-windows/m-p/357836#M65356</guid>
      <dc:creator>pfabrizi</dc:creator>
      <dc:date>2018-04-24T14:58:27Z</dc:date>
    </item>
  </channel>
</rss>

