<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ingesting logs from rsyslog in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-logs-from-rsyslog/m-p/539186#M90331</link>
    <description>&lt;P&gt;No answer??????????????????????????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Feb 2021 14:50:00 GMT</pubDate>
    <dc:creator>awslabspl</dc:creator>
    <dc:date>2021-02-09T14:50:00Z</dc:date>
    <item>
      <title>Ingesting logs from rsyslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-logs-from-rsyslog/m-p/539185#M90330</link>
      <description>&lt;P&gt;Im furious............&lt;/P&gt;&lt;P&gt;2 hosts ( physical ) :: both Ubuntu Server. Read about Splunk and how dibi **bleep**s GHA ( soim)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Host #1: Installed Splunk as in docs, !!!!!!!!!!!!!&lt;/P&gt;&lt;P&gt;Host #2: created FREE Splunk cloud,&lt;/P&gt;&lt;P&gt;Configured everything as in docs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No **bleep**ing logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HELP !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 14:46:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingesting-logs-from-rsyslog/m-p/539185#M90330</guid>
      <dc:creator>awslabspl</dc:creator>
      <dc:date>2021-02-09T14:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: Ingesting logs from rsyslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-logs-from-rsyslog/m-p/539186#M90331</link>
      <description>&lt;P&gt;No answer??????????????????????????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 14:50:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingesting-logs-from-rsyslog/m-p/539186#M90331</guid>
      <dc:creator>awslabspl</dc:creator>
      <dc:date>2021-02-09T14:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Ingesting logs from rsyslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-logs-from-rsyslog/m-p/539194#M90334</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231372"&gt;@awslabspl&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand better because you shared few informations:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you have a physical host that's receiving syslogs with&amp;nbsp;&lt;SPAN&gt;rsyslog,&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;rsyslog receives sysloigs and writes them in files,&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;you want to read thes logs and send them to. Splunk;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;is it correct?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If yes, some questions:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;to which Splunk do you want to send logs: Splunk Cloud or on premise?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;what do you mean saying: "Host #2: created FREE Splunk cloud"?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;the rsyslog server is one of host 1 or host 2 or it's in another host?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;what's your architecture?&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;In few words:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;you can use one of the servers are syslog server and the second as Splunk All-in-one,&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;or you can use an host both as rsyslog server and Splunk All-in-one.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;At firest obviously, you have to check if the rsyslog server is writing syslogs in files.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Then if you have all in the same host (rsyslog and Splunk) you have to configure inputs on Splunk.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If instead you are using two servers, you have to install another Splunk as Heavy Forwarder or a Universal Forwarder on the rsyslog server that sends logs to the Splunk.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In both cases see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.2/Data/Getstartedwithgettingdatain" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.2/Data/Getstartedwithgettingdatain&lt;/A&gt;&amp;nbsp;how to ingest data.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 15:44:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingesting-logs-from-rsyslog/m-p/539194#M90334</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-09T15:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: Ingesting logs from rsyslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-logs-from-rsyslog/m-p/539210#M90336</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;thanks for the answer. I will not go into details as of my arch.&lt;/P&gt;
&lt;P&gt;On the other hand Im 99% sure I will look for other log-management solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 19:43:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingesting-logs-from-rsyslog/m-p/539210#M90336</guid>
      <dc:creator>awslabspl</dc:creator>
      <dc:date>2021-02-09T19:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: Ingesting logs from rsyslog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Ingesting-logs-from-rsyslog/m-p/539255#M90342</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231372"&gt;@awslabspl&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't know why you's so sure to use another solution when the most customers are using Splunk!&lt;/P&gt;&lt;P&gt;Anyway, tell me if you want to continue the analysis of your Use Case.&lt;/P&gt;&lt;P&gt;Ciao and good luck with another solution.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2021 07:29:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Ingesting-logs-from-rsyslog/m-p/539255#M90342</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-10T07:29:33Z</dc:date>
    </item>
  </channel>
</rss>

