<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to forward logs using rsyslog in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-logs-using-rsyslog/m-p/501850#M85510</link>
    <description>&lt;P&gt;Put UF on your rsyslog box and read the files you are already writing.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Dec 2019 17:02:54 GMT</pubDate>
    <dc:creator>starcher</dc:creator>
    <dc:date>2019-12-05T17:02:54Z</dc:date>
    <item>
      <title>How to forward logs using rsyslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-logs-using-rsyslog/m-p/501849#M85509</link>
      <description>&lt;P&gt;There are around 400 servers, which are already forwarding required logs to IBM Qradar using rsyslog. Instead of installing universal forwarders in every server, I want to add one more forwarder (Splunk HWF) in rsyslog config in order to receive logs from every servers. &lt;/P&gt;

&lt;P&gt;• What utility I need to install on log Collector&lt;BR /&gt;
• Can I install this utility on HWF itself as load is very less on this server&lt;BR /&gt;
• Where I will define index and sourcetype details in this case&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 13:24:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-logs-using-rsyslog/m-p/501849#M85509</guid>
      <dc:creator>asharma21193</dc:creator>
      <dc:date>2019-12-05T13:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward logs using rsyslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-logs-using-rsyslog/m-p/501850#M85510</link>
      <description>&lt;P&gt;Put UF on your rsyslog box and read the files you are already writing.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 17:02:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-logs-using-rsyslog/m-p/501850#M85510</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2019-12-05T17:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward logs using rsyslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-logs-using-rsyslog/m-p/501851#M85511</link>
      <description>&lt;P&gt;&lt;A href="http://www.georgestarcher.com/splunk-success-with-syslog/"&gt;http://www.georgestarcher.com/splunk-success-with-syslog/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 17:03:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-logs-using-rsyslog/m-p/501851#M85511</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2019-12-05T17:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward logs using rsyslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-logs-using-rsyslog/m-p/501852#M85512</link>
      <description>&lt;P&gt;it is IBM log collector that we need to decommission. Kindly help with standard solution. &lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 03:31:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-logs-using-rsyslog/m-p/501852#M85512</guid>
      <dc:creator>asharma21193</dc:creator>
      <dc:date>2019-12-06T03:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward logs using rsyslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-logs-using-rsyslog/m-p/501853#M85513</link>
      <description>&lt;P&gt;The standard solution is to run a syslog collector with a UF as stated. You could make a new one and redirect syslog there. &lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 03:44:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-logs-using-rsyslog/m-p/501853#M85513</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2019-12-06T03:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward logs using rsyslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-logs-using-rsyslog/m-p/501854#M85514</link>
      <description>&lt;P&gt;Can I install this utility on HWF itself as load is very less on this server ?&lt;BR /&gt;
 Where I will define index and sourcetype details in this case ?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 03:46:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-logs-using-rsyslog/m-p/501854#M85514</guid>
      <dc:creator>asharma21193</dc:creator>
      <dc:date>2019-12-06T03:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward logs using rsyslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-logs-using-rsyslog/m-p/501855#M85515</link>
      <description>&lt;P&gt;You shouldn't run a heavy forwarder to pickup syslog. You should use a universal forwarder. &lt;/P&gt;

&lt;P&gt;Configuration of either install can do it, however inputs and getting data in can be found at &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.0.0/Data/Getstartedwithgettingdatain"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.0.0/Data/Getstartedwithgettingdatain&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You may want to consult your splunk administrator or professional services if you have not used splunk at all before.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 13:50:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-logs-using-rsyslog/m-p/501855#M85515</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2019-12-06T13:50:25Z</dc:date>
    </item>
  </channel>
</rss>

