<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Forward Logs to Third Party Syslog Server - Not able to receive log data as _raw data in Third Party Syslog Server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forward-Logs-to-Third-Party-Syslog-Server-Not-able-to-receive/m-p/393225#M95632</link>
    <description>&lt;P&gt;I am collecting windows machines logs though Universal Forwarder to Splunk Heavy Forwarder.&lt;/P&gt;

&lt;P&gt;UF STANZA - outputs.conf&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
defaultGroup=windows_index&lt;/P&gt;

&lt;P&gt;[tcpout:windows_index]&lt;BR /&gt;
sendCookedData=false&lt;BR /&gt;
server=192.168.1.172:9997&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Heavy Forwarder STANZA - outputs.conf&lt;/P&gt;

&lt;P&gt;[tcpout:win_log_forw] &lt;BR /&gt;
disabled=false&lt;BR /&gt;
sendCookedData=false&lt;BR /&gt;
server-192.168.1.182:514&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Then forward  log from Splunk Heavy Forwarder  to Splunk Indexer and A third party syslog server.&lt;/P&gt;

&lt;P&gt;Challenge: Third party Syslog server is receiving data as parsed not the raw data &lt;/P&gt;

&lt;P&gt;Goal : need to receive the data on a raw format in the third party Syslog server.&lt;/P&gt;

&lt;P&gt;THIRD PARTY SYSLOG RECEVING LIKE BELOW( NOT RAW)&lt;/P&gt;

&lt;P&gt;2019-02-21T05:24:16.257287+00:00 192.168.1.172 /2019 09:24:14 PM#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 LogName=Security#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 SourceName=Microsoft Windows security auditing.#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 EventCode=4648#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 EventType=0#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 Type=Information#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 ComputerName=WIN-AEG45MM7137#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 TaskCategory=Logon#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 OpCode=Info#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 RecordNumber=782#015&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 23:19:16 GMT</pubDate>
    <dc:creator>lubinak</dc:creator>
    <dc:date>2020-09-29T23:19:16Z</dc:date>
    <item>
      <title>Forward Logs to Third Party Syslog Server - Not able to receive log data as _raw data in Third Party Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-Logs-to-Third-Party-Syslog-Server-Not-able-to-receive/m-p/393225#M95632</link>
      <description>&lt;P&gt;I am collecting windows machines logs though Universal Forwarder to Splunk Heavy Forwarder.&lt;/P&gt;

&lt;P&gt;UF STANZA - outputs.conf&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
defaultGroup=windows_index&lt;/P&gt;

&lt;P&gt;[tcpout:windows_index]&lt;BR /&gt;
sendCookedData=false&lt;BR /&gt;
server=192.168.1.172:9997&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Heavy Forwarder STANZA - outputs.conf&lt;/P&gt;

&lt;P&gt;[tcpout:win_log_forw] &lt;BR /&gt;
disabled=false&lt;BR /&gt;
sendCookedData=false&lt;BR /&gt;
server-192.168.1.182:514&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Then forward  log from Splunk Heavy Forwarder  to Splunk Indexer and A third party syslog server.&lt;/P&gt;

&lt;P&gt;Challenge: Third party Syslog server is receiving data as parsed not the raw data &lt;/P&gt;

&lt;P&gt;Goal : need to receive the data on a raw format in the third party Syslog server.&lt;/P&gt;

&lt;P&gt;THIRD PARTY SYSLOG RECEVING LIKE BELOW( NOT RAW)&lt;/P&gt;

&lt;P&gt;2019-02-21T05:24:16.257287+00:00 192.168.1.172 /2019 09:24:14 PM#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 LogName=Security#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 SourceName=Microsoft Windows security auditing.#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 EventCode=4648#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 EventType=0#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 Type=Information#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 ComputerName=WIN-AEG45MM7137#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 TaskCategory=Logon#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 OpCode=Info#015&lt;BR /&gt;
2019-02-21T05:24:16.257287+00:00 192.168.1.172 RecordNumber=782#015&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:19:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-Logs-to-Third-Party-Syslog-Server-Not-able-to-receive/m-p/393225#M95632</guid>
      <dc:creator>lubinak</dc:creator>
      <dc:date>2020-09-29T23:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Forward Logs to Third Party Syslog Server - Not able to receive log data as _raw data in Third Party Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-Logs-to-Third-Party-Syslog-Server-Not-able-to-receive/m-p/393226#M95633</link>
      <description>&lt;P&gt;Help Please&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2019 19:00:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-Logs-to-Third-Party-Syslog-Server-Not-able-to-receive/m-p/393226#M95633</guid>
      <dc:creator>lubinak</dc:creator>
      <dc:date>2019-02-22T19:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: Forward Logs to Third Party Syslog Server - Not able to receive log data as _raw data in Third Party Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-Logs-to-Third-Party-Syslog-Server-Not-able-to-receive/m-p/393227#M95634</link>
      <description>&lt;P&gt;hello, whether you were able to fix it? I am having same issue as well.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 13:57:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-Logs-to-Third-Party-Syslog-Server-Not-able-to-receive/m-p/393227#M95634</guid>
      <dc:creator>spectrum2035</dc:creator>
      <dc:date>2019-07-03T13:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: Forward Logs to Third Party Syslog Server - Not able to receive log data as _raw data in Third Party Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-Logs-to-Third-Party-Syslog-Server-Not-able-to-receive/m-p/393228#M95635</link>
      <description>&lt;P&gt;The data in this old question looks like raw data to me. This is just plain windows logs being sent line by line over syslog and then the syslog server writing it to disk adding a timestamp and hostname (ip address in this case) in front of each line (because syslog thinks each line is an event).&lt;/P&gt;

&lt;P&gt;Getting rid of timestamp and hostname is probably just a matter of using a different template for writing to disk on the syslog server. Same for the #15, that is the syslog daemon replacing the carriage return (\r) control character with something readable. There is a syslog setting to disable that: &lt;CODE&gt;$EscapeControlCharactersOnReceive off&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;In general I think it is a really bad idea to send this kind of complex multiline events over syslog like this. That is bound to get messed up somehow as syslog daemons are not very good at dealing with multiline data.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 15:06:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-Logs-to-Third-Party-Syslog-Server-Not-able-to-receive/m-p/393228#M95635</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-07-03T15:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Forward Logs to Third Party Syslog Server - Not able to receive log data as _raw data in Third Party Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-Logs-to-Third-Party-Syslog-Server-Not-able-to-receive/m-p/393229#M95636</link>
      <description>&lt;P&gt;Hi FrankVI,&lt;/P&gt;

&lt;P&gt;Thanks for your reply.. I did $EscapeControlCharactersOnReceive off enabled this one but it cuts off the data. I have posted a question in the Splunk answers (Windows Event logs sending to syslog) &lt;A href="https://answers.splunk.com/answers/756494/windows-event-logs-sending-to-syslog.html"&gt;https://answers.splunk.com/answers/756494/windows-event-logs-sending-to-syslog.html&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 15:48:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-Logs-to-Third-Party-Syslog-Server-Not-able-to-receive/m-p/393229#M95636</guid>
      <dc:creator>spectrum2035</dc:creator>
      <dc:date>2019-07-03T15:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: Forward Logs to Third Party Syslog Server - Not able to receive log data as _raw data in Third Party Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-Logs-to-Third-Party-Syslog-Server-Not-able-to-receive/m-p/393230#M95637</link>
      <description>&lt;P&gt;Can you send to the 3rd party server direct from the universal forwarder instead of the heavy forwarder?  The main job of the heavy forwarder is to do some of the parsing work before sending to the indexers.  &lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2019 19:19:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-Logs-to-Third-Party-Syslog-Server-Not-able-to-receive/m-p/393230#M95637</guid>
      <dc:creator>marycordova</dc:creator>
      <dc:date>2019-07-03T19:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: Forward Logs to Third Party Syslog Server - Not able to receive log data as _raw data in Third Party Syslog Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forward-Logs-to-Third-Party-Syslog-Server-Not-able-to-receive/m-p/393231#M95638</link>
      <description>&lt;P&gt;i didnt tried it.. can we send it directly to the 3rd party system using UF. My understanding is that we need to HF.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 08:40:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forward-Logs-to-Third-Party-Syslog-Server-Not-able-to-receive/m-p/393231#M95638</guid>
      <dc:creator>spectrum2035</dc:creator>
      <dc:date>2019-07-04T08:40:43Z</dc:date>
    </item>
  </channel>
</rss>

