<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sourcetypes on UDP syslog data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetypes-on-UDP-syslog-data/m-p/236601#M99063</link>
    <description>&lt;P&gt;It looks like could possibly work for what you need. You can also look into installing syslog-ng, kiwi syslog, or rsyslog on your server. This would allow for more advanced filtering of data and you could send data to different directories as it was being collected.&lt;/P&gt;

&lt;P&gt;From there you could have different monitoring stanzas to look at different directories of data and assign sourcetypes that way. That's probably the cleanest way to do it and the most recommended so that you won't have any data loss in the event that Splunk needs to be restarted or shuts down unexpectedly. &lt;/P&gt;</description>
    <pubDate>Fri, 01 Jul 2016 18:44:19 GMT</pubDate>
    <dc:creator>ryanoconnor</dc:creator>
    <dc:date>2016-07-01T18:44:19Z</dc:date>
    <item>
      <title>Sourcetypes on UDP syslog data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetypes-on-UDP-syslog-data/m-p/236599#M99061</link>
      <description>&lt;P&gt;When receiving syslog data via UDP:514, is there a way to specify the sourcetype based on the IP address of the device sending the data?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2016 17:42:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetypes-on-UDP-syslog-data/m-p/236599#M99061</guid>
      <dc:creator>timmy13</dc:creator>
      <dc:date>2016-07-01T17:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetypes on UDP syslog data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetypes-on-UDP-syslog-data/m-p/236600#M99062</link>
      <description>&lt;P&gt;Interesting related discussion at - &lt;A href="https://answers.splunk.com/answers/38547/sending-certain-logs-from-udp-port-514-to-specific-indexes.html"&gt;Sending certain logs from UDP port 514 to specific indexes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2016 17:52:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetypes-on-UDP-syslog-data/m-p/236600#M99062</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-07-01T17:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetypes on UDP syslog data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetypes-on-UDP-syslog-data/m-p/236601#M99063</link>
      <description>&lt;P&gt;It looks like could possibly work for what you need. You can also look into installing syslog-ng, kiwi syslog, or rsyslog on your server. This would allow for more advanced filtering of data and you could send data to different directories as it was being collected.&lt;/P&gt;

&lt;P&gt;From there you could have different monitoring stanzas to look at different directories of data and assign sourcetypes that way. That's probably the cleanest way to do it and the most recommended so that you won't have any data loss in the event that Splunk needs to be restarted or shuts down unexpectedly. &lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2016 18:44:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetypes-on-UDP-syslog-data/m-p/236601#M99063</guid>
      <dc:creator>ryanoconnor</dc:creator>
      <dc:date>2016-07-01T18:44:19Z</dc:date>
    </item>
  </channel>
</rss>

