<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using Splunk universal forwarder to forward log into Kiwi Syslog Server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327480#M93658</link>
    <description>&lt;P&gt;Is there any ways for me to forward log into Kiwi Syslog Server by using Splunk universal forwarder?&lt;/P&gt;</description>
    <pubDate>Tue, 05 Dec 2017 07:01:51 GMT</pubDate>
    <dc:creator>ailing1909</dc:creator>
    <dc:date>2017-12-05T07:01:51Z</dc:date>
    <item>
      <title>Using Splunk universal forwarder to forward log into Kiwi Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327480#M93658</link>
      <description>&lt;P&gt;Is there any ways for me to forward log into Kiwi Syslog Server by using Splunk universal forwarder?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 07:01:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327480#M93658</guid>
      <dc:creator>ailing1909</dc:creator>
      <dc:date>2017-12-05T07:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk universal forwarder to forward log into Kiwi Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327481#M93659</link>
      <description>&lt;P&gt;First of all, why on earth would you want to do that?  Send it to Splunk instead.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 14:14:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327481#M93659</guid>
      <dc:creator>lycollicott</dc:creator>
      <dc:date>2017-12-05T14:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk universal forwarder to forward log into Kiwi Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327482#M93660</link>
      <description>&lt;P&gt;Hi @ailing1909,&lt;/P&gt;

&lt;P&gt;From Universal Forwarder you can route data to TCP server without filtering raw data but not UDP. If your syslog can accept data on TCP port and you do not want to filter raw data then you can configure UF outputs.conf to send data to Syslog server, please refer &lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.3/Forwarding/Forwarddatatothird-partysystemsd#TCP_data"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.3/Forwarding/Forwarddatatothird-partysystemsd#TCP_data&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you want to send data from UF to Syslog server over UDP then you need to use Heavy Forwarder, you can't achieve it via UF.&lt;/P&gt;

&lt;P&gt;I hope this helps.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Harshil&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 14:33:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327482#M93660</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-12-05T14:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk universal forwarder to forward log into Kiwi Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327483#M93661</link>
      <description>&lt;P&gt;thanks for the help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 00:50:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327483#M93661</guid>
      <dc:creator>ailing1909</dc:creator>
      <dc:date>2017-12-06T00:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk universal forwarder to forward log into Kiwi Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327484#M93662</link>
      <description>&lt;P&gt;hi! is there other way that i can do so? as i configure UF output.conf file, however i still didn't manage to send through&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 02:04:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327484#M93662</guid>
      <dc:creator>ailing1909</dc:creator>
      <dc:date>2017-12-07T02:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk universal forwarder to forward log into Kiwi Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327485#M93663</link>
      <description>&lt;P&gt;Can you please let us know how you configured on UF and in which configuration files?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 03:34:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327485#M93663</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-12-07T03:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk universal forwarder to forward log into Kiwi Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327486#M93664</link>
      <description>&lt;P&gt;i config in UF output.conf under UF\etc\system\local\output.conf this what i did&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
server = 192.168.1.113:9997&lt;BR /&gt;
sendCookedData = false&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = 192.168.1.113:9997&lt;/P&gt;

&lt;P&gt;[tcpout-server://192.168.1.113:9997]&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 03:45:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327486#M93664</guid>
      <dc:creator>ailing1909</dc:creator>
      <dc:date>2017-12-07T03:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Using Splunk universal forwarder to forward log into Kiwi Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327487#M93665</link>
      <description>&lt;P&gt;Config which you have provided it looks like UF to Indexer configuration. &lt;/P&gt;

&lt;P&gt;If you want to send all data from UF to Syslog server over &lt;STRONG&gt;TCP&lt;/STRONG&gt; only then please use below configuration in outputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = syslog_group

[tcpout:fastlane]
server = &amp;lt;SYSLOG IP&amp;gt;:&amp;lt;SYSLOG TCP PORT&amp;gt;
sendCookedData = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If you want to send data to Indexer and Syslog server over &lt;STRONG&gt;TCP&lt;/STRONG&gt; then you can use below configuration&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = indexer_group, syslog_group

[tcpout:indexer_group]
server = &amp;lt;IDX IP&amp;gt;:&amp;lt;IDX PORT&amp;gt;

[tcpout:syslog_group]
server = &amp;lt;SYSLOG IP&amp;gt;:&amp;lt;SYSLOG TCP PORT&amp;gt;
sendCookedData = false
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 07 Dec 2017 04:20:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-Splunk-universal-forwarder-to-forward-log-into-Kiwi-Syslog/m-p/327487#M93665</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-12-07T04:20:27Z</dc:date>
    </item>
  </channel>
</rss>

