<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder and parsing events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-parsing-events/m-p/44426#M8304</link>
    <description>&lt;P&gt;Filtering can only be done on Splunk instances that perform parsing, which a Universal Forwarder doesn't. So you'd need a full Splunk instance acting as a forwarder (a "heavy forwarder").&lt;/P&gt;</description>
    <pubDate>Wed, 27 Feb 2013 18:27:10 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2013-02-27T18:27:10Z</dc:date>
    <item>
      <title>Universal Forwarder and parsing events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-parsing-events/m-p/44423#M8301</link>
      <description>&lt;P&gt;We are in the process of replacing Snare for Windows at Client machines (Windows 7) with a splunk Forwarder. Which Splunk Forwarder would you suggest we install at the client and the process/procedure to parse the various events?&lt;/P&gt;

&lt;P&gt;Thank you for your help.&lt;/P&gt;

&lt;P&gt;Unis&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2013 22:28:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-parsing-events/m-p/44423#M8301</guid>
      <dc:creator>uayub</dc:creator>
      <dc:date>2013-02-26T22:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and parsing events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-parsing-events/m-p/44424#M8302</link>
      <description>&lt;P&gt;Event "parsing", or what in Splunk is more commonly called "field extraction", is done at search-time, not index-time. Universal Forwarders simply read raw log data and forward it - that's it.&lt;/P&gt;

&lt;P&gt;There aren't very many different kinds of Splunk forwarders to choose from, so I'm really not sure what you're after. A Universal Forwarder is what you likely want to use unless you have good reasons for choosing a full-fledged Splunk instance acting as a forwarder (and know what you're doing).&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2013 22:57:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-parsing-events/m-p/44424#M8302</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-02-26T22:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and parsing events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-parsing-events/m-p/44425#M8303</link>
      <description>&lt;P&gt;Thanks Ayn for the reply. Basically we need to filter the events generated at the client and then forward it to the indexer. How could we achieve this ?&lt;BR /&gt;
Thank you.&lt;BR /&gt;
Unis&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2013 18:12:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-parsing-events/m-p/44425#M8303</guid>
      <dc:creator>uayub</dc:creator>
      <dc:date>2013-02-27T18:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder and parsing events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-parsing-events/m-p/44426#M8304</link>
      <description>&lt;P&gt;Filtering can only be done on Splunk instances that perform parsing, which a Universal Forwarder doesn't. So you'd need a full Splunk instance acting as a forwarder (a "heavy forwarder").&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2013 18:27:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-and-parsing-events/m-p/44426#M8304</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-02-27T18:27:10Z</dc:date>
    </item>
  </channel>
</rss>

