<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Critical Syslog Server Tricks in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Critical-Syslog-Server-Tricks/m-p/556019#M92062</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have a large environment to deploy Splunk cloud and trying to leverage the syslog server (Rsyslog) in front of a load balancer, with UF on top.&lt;/P&gt;&lt;P&gt;As per my research, I have found a wonderful document which automates the inputs.conf and props.conf creation based on an excel sheet, relying on separation based on devices hostnames.&lt;/P&gt;&lt;P&gt;The link for documentation is here:&amp;nbsp;&lt;A href="https://conf.splunk.com/files/2017/slides/the-critical-syslog-tricks-that-no-one-seems-to-know-about.pdf" target="_blank" rel="noopener"&gt;https://conf.splunk.com/files/2017/slides/the-critical-syslog-tricks-that-no-one-seems-to-know-about.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I'm wondering if anyone has used the provided scripts for this automation? I couldn't find any explanation on how the python scripts work?&lt;BR /&gt;&lt;BR /&gt;link to gitlab:&amp;nbsp;&lt;A href="https://gitlab.com/rationalcyber/splunk_syslog_inputs" target="_blank" rel="noopener"&gt;https://gitlab.com/rationalcyber/splunk_syslog_inputs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;link to script:&amp;nbsp;&lt;A href="https://gitlab.com/rationalcyber/splunk_syslog_inputs/-/tree/master/src" target="_blank" rel="noopener"&gt;https://gitlab.com/rationalcyber/splunk_syslog_inputs/-/tree/master/src&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Wed, 16 Jun 2021 16:42:40 GMT</pubDate>
    <dc:creator>aydinmo</dc:creator>
    <dc:date>2021-06-16T16:42:40Z</dc:date>
    <item>
      <title>Critical Syslog Server Tricks</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Critical-Syslog-Server-Tricks/m-p/556019#M92062</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have a large environment to deploy Splunk cloud and trying to leverage the syslog server (Rsyslog) in front of a load balancer, with UF on top.&lt;/P&gt;&lt;P&gt;As per my research, I have found a wonderful document which automates the inputs.conf and props.conf creation based on an excel sheet, relying on separation based on devices hostnames.&lt;/P&gt;&lt;P&gt;The link for documentation is here:&amp;nbsp;&lt;A href="https://conf.splunk.com/files/2017/slides/the-critical-syslog-tricks-that-no-one-seems-to-know-about.pdf" target="_blank" rel="noopener"&gt;https://conf.splunk.com/files/2017/slides/the-critical-syslog-tricks-that-no-one-seems-to-know-about.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I'm wondering if anyone has used the provided scripts for this automation? I couldn't find any explanation on how the python scripts work?&lt;BR /&gt;&lt;BR /&gt;link to gitlab:&amp;nbsp;&lt;A href="https://gitlab.com/rationalcyber/splunk_syslog_inputs" target="_blank" rel="noopener"&gt;https://gitlab.com/rationalcyber/splunk_syslog_inputs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;link to script:&amp;nbsp;&lt;A href="https://gitlab.com/rationalcyber/splunk_syslog_inputs/-/tree/master/src" target="_blank" rel="noopener"&gt;https://gitlab.com/rationalcyber/splunk_syslog_inputs/-/tree/master/src&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 16:42:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Critical-Syslog-Server-Tricks/m-p/556019#M92062</guid>
      <dc:creator>aydinmo</dc:creator>
      <dc:date>2021-06-16T16:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: Critical Syslog Server Tricks</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Critical-Syslog-Server-Tricks/m-p/640386#M109302</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/212476"&gt;@aydinmo&lt;/a&gt;&amp;nbsp;did you get this resolved?&amp;nbsp; I'm one of the presenters of that 2017 .conf talk; please let me know if there were any hurdles you couldn't get past.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 17:07:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Critical-Syslog-Server-Tricks/m-p/640386#M109302</guid>
      <dc:creator>evilgeorge</dc:creator>
      <dc:date>2023-04-18T17:07:04Z</dc:date>
    </item>
  </channel>
</rss>

