<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to onboard unknown source SC4S? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-onboard-unknown-source-SC4S/m-p/530865#M89335</link>
    <description>&lt;P&gt;Hello Splunkers!&lt;BR /&gt;&lt;BR /&gt;We have deployed SC4S and it works fine for Trend but we're now using it for VPN (Aviatrix) which doesn't have a prebuilt source.&lt;/P&gt;
&lt;P&gt;Data coming into main on the fallback so we're good to go, but looking for details on HOW to add custom sources.&amp;nbsp; I've been through&amp;nbsp;&lt;A href="https://splunk-connect-for-syslog.readthedocs.io/en/master/" target="_blank" rel="noopener"&gt;https://splunk-connect-for-syslog.readthedocs.io/en/master/&lt;/A&gt;&amp;nbsp;many times but nothing really explains it.&lt;/P&gt;
&lt;P&gt;We've deployed&amp;nbsp;Bring Your Own Environment and everything is under&amp;nbsp;/etc/syslog-ng.&lt;BR /&gt;&lt;BR /&gt;Would really appreciate some steps on how to add new source!&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 05 May 2022 22:47:13 GMT</pubDate>
    <dc:creator>johnansett</dc:creator>
    <dc:date>2022-05-05T22:47:13Z</dc:date>
    <item>
      <title>How to onboard unknown source SC4S?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-onboard-unknown-source-SC4S/m-p/530865#M89335</link>
      <description>&lt;P&gt;Hello Splunkers!&lt;BR /&gt;&lt;BR /&gt;We have deployed SC4S and it works fine for Trend but we're now using it for VPN (Aviatrix) which doesn't have a prebuilt source.&lt;/P&gt;
&lt;P&gt;Data coming into main on the fallback so we're good to go, but looking for details on HOW to add custom sources.&amp;nbsp; I've been through&amp;nbsp;&lt;A href="https://splunk-connect-for-syslog.readthedocs.io/en/master/" target="_blank" rel="noopener"&gt;https://splunk-connect-for-syslog.readthedocs.io/en/master/&lt;/A&gt;&amp;nbsp;many times but nothing really explains it.&lt;/P&gt;
&lt;P&gt;We've deployed&amp;nbsp;Bring Your Own Environment and everything is under&amp;nbsp;/etc/syslog-ng.&lt;BR /&gt;&lt;BR /&gt;Would really appreciate some steps on how to add new source!&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 22:47:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-onboard-unknown-source-SC4S/m-p/530865#M89335</guid>
      <dc:creator>johnansett</dc:creator>
      <dc:date>2022-05-05T22:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: Onboard unknown source SC4S</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-onboard-unknown-source-SC4S/m-p/583324#M102781</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/167954"&gt;@johnansett&lt;/a&gt;&amp;nbsp;I am new to splunk and want to send the syslog data to splunk,&lt;/P&gt;&lt;P&gt;My question is where did to setup the SC4S is it on the host device which generates logs or some other location?&lt;/P&gt;&lt;P&gt;Thanks you.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 06:43:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-onboard-unknown-source-SC4S/m-p/583324#M102781</guid>
      <dc:creator>blbr123</dc:creator>
      <dc:date>2022-02-02T06:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Onboard unknown source SC4S</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-onboard-unknown-source-SC4S/m-p/596632#M104155</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/167954"&gt;@johnansett&lt;/a&gt;&amp;nbsp;can you help with the steps for setting up the sc4s server for getting syslog data into Splunk&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 22:37:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-onboard-unknown-source-SC4S/m-p/596632#M104155</guid>
      <dc:creator>abk_hexion</dc:creator>
      <dc:date>2022-05-05T22:37:32Z</dc:date>
    </item>
  </channel>
</rss>

