<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forward logs to third party and no duplicates in splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/540153#M90460</link>
    <description>&lt;P&gt;What's the point of sending data to Splunk if it won't be indexed?&amp;nbsp; Send the syslog data directly to the syslog server.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Feb 2021 19:07:08 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-02-16T19:07:08Z</dc:date>
    <item>
      <title>Forward logs to third party and no duplicates in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/540147#M90459</link>
      <description>&lt;P&gt;I want to forward logs to third party system (syslog) without index these data into splunk but i can't accomplish it, help.&lt;/P&gt;&lt;P&gt;On my heavy forwarder i set up outputs.conf, transforms.conf, props.conf as follow:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;outuputs.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[syslog:my_syslog_group]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;server = &amp;lt;IP&amp;gt;:PORT&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;transforms.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[send_to_syslog]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;REGEX = MY REGEX&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DEST_KEY = _SYSLOG_ROUTING&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;FORMAT = my_syslog_group&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[not_send_to_syslog]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;REGEX = MY REGEX&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DEST_KEY =queue&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;FORMAT =nullQueue&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[source::MY_SOURCE]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;TRANSFORMS-t0=send_to_syslog,not_send_to_syslog&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;In this way logs don't forward to my syslog, they will be just deleted and not indexed. Removing&amp;nbsp;&lt;EM&gt;[not_send_to_syslog]&lt;/EM&gt; from props and transforms data will be indexed on splunk and also forwarded to syslog.&lt;BR /&gt;&lt;BR /&gt;How can i achieve my problem, sending data to syslog and not indexing them on splunk? Thanks in advantage to those who will help me.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 18:48:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/540147#M90459</guid>
      <dc:creator>Anto</dc:creator>
      <dc:date>2021-02-16T18:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Forward logs to third party and no duplicates in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/540153#M90460</link>
      <description>&lt;P&gt;What's the point of sending data to Splunk if it won't be indexed?&amp;nbsp; Send the syslog data directly to the syslog server.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 19:07:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/540153#M90460</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-02-16T19:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: Forward logs to third party and no duplicates in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/540156#M90461</link>
      <description>&lt;P&gt;Because i don't need them for the analysis in Splunk but i want to preserve the logs&amp;nbsp; without exceed my license just for 2 GB. So you are telling me that this isn't possible to do directly from splunk? Thank you for your reply, i want just to understand&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 19:29:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/540156#M90461</guid>
      <dc:creator>Anto</dc:creator>
      <dc:date>2021-02-16T19:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: Forward logs to third party and no duplicates in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/540237#M90473</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229274"&gt;@Anto&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Can you try changing the order of transforms in props.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[source::MY_SOURCE]
TRANSFORMS-t0=not_send_to_syslog, send_to_syslog&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 12:55:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/540237#M90473</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-17T12:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: Forward logs to third party and no duplicates in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/540240#M90474</link>
      <description>&lt;P&gt;Thank you for your answer but it didn't help. Logs aren't forwarded to syslog and they entered in nullqueue so i don't saw them also in splunk. Any other ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 13:09:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/540240#M90474</guid>
      <dc:creator>Anto</dc:creator>
      <dc:date>2021-02-17T13:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: Forward logs to third party and no duplicates in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/540281#M90482</link>
      <description>&lt;P&gt;I find out the solution. In the transform.conf just replace DEST_KEY as follow:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[not_send_to_syslog]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;REGEX = MY REGEX&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DEST_KEY =_TCP_ROUTING&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;FORMAT =nullQueue&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;All done now. thanks to all&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 17:21:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/540281#M90482</guid>
      <dc:creator>Anto</dc:creator>
      <dc:date>2021-02-17T17:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: Forward logs to third party and no duplicates in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/650548#M110535</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;plese help , how can i send data directly to&amp;nbsp; remote system , or syslog without indexing.&lt;/P&gt;&lt;P&gt;please provide the config settings for inputs.conf, outputs.conf, props.conf , transforms.conf&lt;/P&gt;&lt;P&gt;you help is appreciated.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 12:21:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/650548#M110535</guid>
      <dc:creator>anilkapoor123</dc:creator>
      <dc:date>2023-07-14T12:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Forward logs to third party and no duplicates in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/650554#M110538</link>
      <description>&lt;P&gt;This thread is two years old with an accepted answer.&amp;nbsp; For better chances at getting an answer, please post a new question.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 12:52:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/650554#M110538</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-14T12:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: Forward logs to third party and no duplicates in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/650555#M110539</link>
      <description>&lt;P&gt;1. This thread is over two years old. It's usually better to start a new one instead of digging up such antiquities. Possibly linking to the old one for reference what you already found.&lt;/P&gt;&lt;P&gt;2. You already had a solution in this thread.&lt;/P&gt;&lt;P&gt;3. If you don't want to use the data in Splunk in any way why send it there in the first place? It seems to make more sense to send it directly to the destination system.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 12:59:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/650555#M110539</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-07-14T12:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: Forward logs to third party and no duplicates in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/650945#M110579</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;without forwarding data to splunk heavy forwarder i cannot send to syslog server&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you have any alernative for this like to&amp;nbsp;&lt;/P&gt;&lt;P&gt;forward ftop logs from window directory to syslog server without using splunk&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 08:04:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/650945#M110579</guid>
      <dc:creator>anilkapoor123</dc:creator>
      <dc:date>2023-07-18T08:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Forward logs to third party and no duplicates in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/650949#M110580</link>
      <description>&lt;P&gt;If you just want to pick up log files from local directory on windows computer and send the events from them to a syslog destination, use a syslog daemon for windows (Like NXLog, or Kiwi).&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 08:22:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-logs-to-third-party-and-no-duplicates-in-splunk/m-p/650949#M110580</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-07-18T08:22:53Z</dc:date>
    </item>
  </channel>
</rss>

