<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How Do You Forward Data to Syslog Server and Indexers? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-Do-You-Forward-Data-to-Syslog-Server-and-Indexers/m-p/419717#M73938</link>
    <description>&lt;P&gt;Hey rajindurbal,&lt;/P&gt;

&lt;P&gt;To forward data from heavy forwarder to syslog server .&lt;BR /&gt;
Refer : &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;To forward data to indexers as well:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Forwardsearchheaddata"&gt;https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Forwardsearchheaddata&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Aug 2018 10:48:15 GMT</pubDate>
    <dc:creator>deepashri_123</dc:creator>
    <dc:date>2018-08-23T10:48:15Z</dc:date>
    <item>
      <title>How Do You Forward Data to Syslog Server and Indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-Do-You-Forward-Data-to-Syslog-Server-and-Indexers/m-p/419715#M73936</link>
      <description>&lt;P&gt;What I am trying to do is to get a particular source type forwarded from the heavy forwarder to a syslog server. In addition, I want the data to also go to my indexers. Is it possible to do this? What configuration would be needed? &lt;/P&gt;</description>
      <pubDate>Thu, 23 Aug 2018 01:35:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-Do-You-Forward-Data-to-Syslog-Server-and-Indexers/m-p/419715#M73936</guid>
      <dc:creator>rajindurbal</dc:creator>
      <dc:date>2018-08-23T01:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: How Do You Forward Data to Syslog Server and Indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-Do-You-Forward-Data-to-Syslog-Server-and-Indexers/m-p/419716#M73937</link>
      <description>&lt;P&gt;check this link:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.2/Forwarding/Forwarddatatothird-partysystemsd#Forward_a_subset_of_data"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.2/Forwarding/Forwarddatatothird-partysystemsd#Forward_a_subset_of_data&lt;/A&gt;&lt;/P&gt;

&lt;H1&gt;mention the source type and configure props.conf &amp;amp; transforms.conf followed by outputs.conf&lt;/H1&gt;

&lt;P&gt;Also, check the below Splunk accepted answer&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/211403/how-to-configure-inputsconf-and-outputsconf-on-the.html"&gt;https://answers.splunk.com/answers/211403/how-to-configure-inputsconf-and-outputsconf-on-the.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Aug 2018 06:50:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-Do-You-Forward-Data-to-Syslog-Server-and-Indexers/m-p/419716#M73937</guid>
      <dc:creator>vinkumar_splunk</dc:creator>
      <dc:date>2018-08-23T06:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: How Do You Forward Data to Syslog Server and Indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-Do-You-Forward-Data-to-Syslog-Server-and-Indexers/m-p/419717#M73938</link>
      <description>&lt;P&gt;Hey rajindurbal,&lt;/P&gt;

&lt;P&gt;To forward data from heavy forwarder to syslog server .&lt;BR /&gt;
Refer : &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;To forward data to indexers as well:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Forwardsearchheaddata"&gt;https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Forwardsearchheaddata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Aug 2018 10:48:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-Do-You-Forward-Data-to-Syslog-Server-and-Indexers/m-p/419717#M73938</guid>
      <dc:creator>deepashri_123</dc:creator>
      <dc:date>2018-08-23T10:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: How Do You Forward Data to Syslog Server and Indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-Do-You-Forward-Data-to-Syslog-Server-and-Indexers/m-p/419718#M73939</link>
      <description>&lt;P&gt;Hi @rajindurbal  - Did one of the answers below help provide a solution to your question? If yes, please click “Accept” below the best answer to resolve this post and upvote anything that was helpful. If no, please leave a comment with more feedback. Thanks for posting!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Aug 2018 23:44:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-Do-You-Forward-Data-to-Syslog-Server-and-Indexers/m-p/419718#M73939</guid>
      <dc:creator>mstjohn_splunk</dc:creator>
      <dc:date>2018-08-23T23:44:48Z</dc:date>
    </item>
  </channel>
</rss>

