<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to add new SSL input to heavy forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-new-SSL-input-to-heavy-forwarder/m-p/440610#M76807</link>
    <description>&lt;P&gt;Sorry. I fixed the link&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;So you are sending logs over classic syslog channels.&lt;BR /&gt;
You can use the splunk UDP/TCP inputs described on the link&lt;BR /&gt;
or you can use a syslog server to write the logs to disk, and have splunk monitor the files.&lt;/P&gt;</description>
    <pubDate>Fri, 15 Mar 2019 17:13:54 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2019-03-15T17:13:54Z</dc:date>
    <item>
      <title>How to add new SSL input to heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-new-SSL-input-to-heavy-forwarder/m-p/440607#M76804</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I am trying to add PAN traps logs into splunk. It is syslog and traps sends the log on SSL. I got the SSL certs. I need some help is setting up SSL connection from forwarder to traps cloud. &lt;/P&gt;

&lt;P&gt;Anyone can help?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 15:13:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-new-SSL-input-to-heavy-forwarder/m-p/440607#M76804</guid>
      <dc:creator>graju89</dc:creator>
      <dc:date>2019-03-14T15:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to add new SSL input to heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-new-SSL-input-to-heavy-forwarder/m-p/440608#M76805</link>
      <description>&lt;P&gt;The docs recommend to use an intermediary software to receive the snmp traps (with ssl or not), then write them to a file on disk.&lt;BR /&gt;
The use splunk to monitor the file and index it.&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/SendSNMPeventstoSplunk"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/SendSNMPeventstoSplunk&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The other input (Tcp with ssl) is for syslog, but I am not sure if this is appropriate for SNMP traps data.&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 21:39:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-new-SSL-input-to-heavy-forwarder/m-p/440608#M76805</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2019-03-14T21:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to add new SSL input to heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-new-SSL-input-to-heavy-forwarder/m-p/440609#M76806</link>
      <description>&lt;P&gt;Hi YannK,&lt;/P&gt;

&lt;P&gt;Thanks for your reply. It is not SNMP traps. It is PAN traps log. The second link you mentioned, is not opening.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 16:16:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-new-SSL-input-to-heavy-forwarder/m-p/440609#M76806</guid>
      <dc:creator>graju89</dc:creator>
      <dc:date>2019-03-15T16:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to add new SSL input to heavy forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-new-SSL-input-to-heavy-forwarder/m-p/440610#M76807</link>
      <description>&lt;P&gt;Sorry. I fixed the link&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;So you are sending logs over classic syslog channels.&lt;BR /&gt;
You can use the splunk UDP/TCP inputs described on the link&lt;BR /&gt;
or you can use a syslog server to write the logs to disk, and have splunk monitor the files.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 17:13:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-new-SSL-input-to-heavy-forwarder/m-p/440610#M76807</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2019-03-15T17:13:54Z</dc:date>
    </item>
  </channel>
</rss>

