<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UDP data input in Installation</title>
    <link>https://community.splunk.com/t5/Installation/UDP-data-input/m-p/677505#M13641</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; So I just have to create an index wit the same name on the indexers?&lt;/P&gt;</description>
    <pubDate>Wed, 14 Feb 2024 01:18:59 GMT</pubDate>
    <dc:creator>jmrubio</dc:creator>
    <dc:date>2024-02-14T01:18:59Z</dc:date>
    <item>
      <title>UDP data input</title>
      <link>https://community.splunk.com/t5/Installation/UDP-data-input/m-p/677487#M13638</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;I am trying to send data to Splunk using UDP, I tried to set it up using the documentation and seen a few videos on how to set it up but can't get it right. I have the data coming into my HF from network devices and then should be sent to my indexers. After going through the set up I get this error message "&lt;SPAN&gt;&lt;SPAN class=""&gt;Search peer splunk_indexer_02 has the following message: Received event for unconfigured/disabled/deleted index=&amp;lt;index&amp;gt; with source="source::udp:514" host="host::xx.xx.xx.xx" sourcetype="sourcetype::&amp;lt;sourcetype&amp;gt;. So far received events from 2 missing index(es).&lt;/SPAN&gt;&lt;/SPAN&gt;" I created a new index during the set up but there is no data to search.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 21:46:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/UDP-data-input/m-p/677487#M13638</guid>
      <dc:creator>jmrubio</dc:creator>
      <dc:date>2024-02-13T21:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: UDP data input</title>
      <link>https://community.splunk.com/t5/Installation/UDP-data-input/m-p/677504#M13640</link>
      <description>&lt;P&gt;It sounds like the new index was created on the HF, but not on the indexers.&amp;nbsp; The index must exist on the indexers so they have a place to store the data.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 01:17:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/UDP-data-input/m-p/677504#M13640</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-02-14T01:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: UDP data input</title>
      <link>https://community.splunk.com/t5/Installation/UDP-data-input/m-p/677505#M13641</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; So I just have to create an index wit the same name on the indexers?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 01:18:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/UDP-data-input/m-p/677505#M13641</guid>
      <dc:creator>jmrubio</dc:creator>
      <dc:date>2024-02-14T01:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: UDP data input</title>
      <link>https://community.splunk.com/t5/Installation/UDP-data-input/m-p/677532#M13642</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259214"&gt;@jmrubio&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;if you have this message on Indexer, it seems that you forgot to create the index on Indexers or that maybe there's a difference between the index name and the index that you configured in the inputs.con of the HF.&lt;/P&gt;&lt;P&gt;If the message is in the HF, it seems that there's an issue in forwardring configuration.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 07:35:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/UDP-data-input/m-p/677532#M13642</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-02-14T07:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: UDP data input</title>
      <link>https://community.splunk.com/t5/Installation/UDP-data-input/m-p/677550#M13644</link>
      <description>&lt;P&gt;&amp;nbsp;Here are some useful references:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.1.2308/Data/Monitornetworkports" target="_blank" rel="noopener"&gt;Get data from TCP and UDP ports - Splunk Documentation&lt;BR /&gt;&lt;/A&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.0/Indexer/Setupmultipleindexes" target="_blank" rel="noopener"&gt;Create custom indexes - Splunk Documentation&lt;BR /&gt;&lt;BR /&gt;Note the section in the first link, copied below, where it says that you have to define the inputs stanza attributes so that the data ingested is properly indexed.&lt;BR /&gt;&lt;BR /&gt;For the second link, the "Create Event Indexes" section might be orienting for you.&lt;BR /&gt;&lt;BR /&gt;==================&lt;/A&gt;&lt;/P&gt;&lt;H3&gt;&lt;SPAN class=""&gt;Configure a UDP network input&lt;/SPAN&gt;&lt;/H3&gt;&lt;P&gt;This type of input stanza is similar to the TCP type, except that it listens on a UDP network port. If you provide&lt;SPAN&gt;&amp;nbsp;&amp;lt;remote server&amp;gt;, the port that you specify only accepts data from that host. If you don't specify anything for&lt;SPAN&gt;&amp;nbsp;&amp;lt;remote server&amp;gt;, the port accepts data that comes from any host.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;PRE&gt;[udp://&amp;lt;remote server&amp;gt;:&amp;lt;port&amp;gt;]
&amp;lt;attrbute1&amp;gt; = &amp;lt;val1&amp;gt;
&amp;lt;attrbute2&amp;gt; = &amp;lt;val2&amp;gt;
...&lt;/PRE&gt;&lt;P&gt;The following settings control how the Splunk platform stores the data:&lt;/P&gt;Setting Description Default &lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;host = &amp;lt;string&amp;gt;&lt;/TD&gt;&lt;TD&gt;Sets the host field to a static value for this stanza. Also sets the host key initial value.&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Splunk Cloud Platform&lt;SPAN&gt;&amp;nbsp;uses this key during parsing and indexing, in particular to set the host field. It also uses the host field at search time. The&lt;SPAN&gt;&amp;nbsp;&amp;lt;string&amp;gt;&lt;SPAN&gt;&amp;nbsp;is prepended with&lt;SPAN&gt;&amp;nbsp;host::.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;The IP address or fully-qualified domain name of the host where the data originated.&lt;/TD&gt;&lt;TD&gt;index = &amp;lt;string&amp;gt;&lt;/TD&gt;&lt;TD&gt;Sets the index where&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Splunk Cloud Platform&lt;SPAN&gt;&amp;nbsp;stores events from this input. The&lt;SPAN&gt;&amp;nbsp;&amp;lt;string&amp;gt;&lt;SPAN&gt;&amp;nbsp;is prepended with&lt;SPAN&gt;&amp;nbsp;index::.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;main&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;or whatever you set the default index to&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;sourcetype = &amp;lt;string&amp;gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Sets the sourcetype field for events from this input. Also declares the source type for this data, as opposed to letting&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Splunk Cloud Platform&lt;SPAN&gt;&amp;nbsp;determine it. This is important both for searchability and for applying the relevant formatting for this type of data during parsing and indexing.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Sets the sourcetype key initial value.&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Splunk Cloud Platform&lt;SPAN&gt;&amp;nbsp;uses the key during parsing and indexing, in particular to set the source type field during indexing. It also uses the source type field that it used at search time.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The&lt;SPAN&gt;&amp;nbsp;&amp;lt;string&amp;gt;&lt;SPAN&gt;&amp;nbsp;is prepended with&lt;SPAN&gt;&amp;nbsp;sourcetype::.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Splunk Cloud Platform&lt;SPAN&gt;&amp;nbsp;picks a source type based on various aspects of the data. There is no hard-coded default.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;source = &amp;lt;string&amp;gt;&lt;/TD&gt;&lt;TD&gt;Sets the source field for events from this input. The&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;lt;string&amp;gt;&lt;SPAN&gt;&amp;nbsp;is prepended with&lt;SPAN&gt;&amp;nbsp;source::.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P class=""&gt;Do not override the source key unless absolutely necessary. The input layer provides a more accurate string to aid in problem analysis and investigation by recording the file from which the data is retrieved. Consider use of source types, tagging, and search wildcards before overriding this value.&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;The input file path.&lt;/TD&gt;&lt;TD&gt;indexQueue&lt;/TD&gt;&lt;TD&gt;Sets where the input processor deposits the events that it reads. Set to&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;parsingQueue&lt;SPAN&gt;&amp;nbsp;to apply the props.conf file and other parsing rules to your data. Set to&lt;SPAN&gt;&amp;nbsp;indexQueue&lt;SPAN&gt;&amp;nbsp;to send your data directly into the index.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;parsingQueue&lt;/TD&gt;&lt;TD&gt;_rcvbuf = &amp;lt;integer&amp;gt;&lt;/TD&gt;&lt;TD&gt;Sets the receive buffer for the UDP port, in bytes. If the value is 0 or negative,&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Splunk Cloud Platform&lt;SPAN&gt;&amp;nbsp;ignores the value.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;1,572,864 unless the value is too large for an OS. In this case,&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Splunk Cloud Platform&lt;SPAN&gt;&amp;nbsp;halves the value from this default continuously until the buffer size is at an acceptable level.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;no_priority_stripping = true | false&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Sets how Splunk Enterprise handles receiving syslog data.&lt;/P&gt;&lt;P&gt;If you set this setting to true,&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Splunk Cloud Platform&lt;SPAN&gt;&amp;nbsp;does not strip the &amp;lt;priority&amp;gt; syslog field from received events.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Depending on how you set this setting,&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Splunk Cloud Platform&lt;SPAN&gt;&amp;nbsp;also sets event timestamps differently. When set to true,&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Splunk Cloud Platform&lt;SPAN&gt;&amp;nbsp;honors the timestamp as it comes from the source. When set to false, Splunk Enterprise assigns events the local time.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;false (&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Splunk Cloud Platform&lt;SPAN&gt;&amp;nbsp;strips &amp;lt;priority&amp;gt;.)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;no_appending_timestamp = true | false&lt;/TD&gt;&lt;TD&gt;Sets how&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Splunk Cloud Platform&lt;SPAN&gt;&amp;nbsp;applies timestamps and hosts to events.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;If you set this setting to true,&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Splunk Cloud Platform&lt;SPAN&gt;&amp;nbsp;does not append a timestamp and host to received events.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;Do not configure this setting if you want to append timestamp and host to received events.&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;false (&lt;SPAN class=""&gt;Splunk Cloud Platform&lt;SPAN&gt;&amp;nbsp;appends timestamps and hosts to events)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259214"&gt;@jmrubio&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 12:36:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/UDP-data-input/m-p/677550#M13644</guid>
      <dc:creator>JohnEGones</dc:creator>
      <dc:date>2024-02-14T12:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: UDP data input</title>
      <link>https://community.splunk.com/t5/Installation/UDP-data-input/m-p/677554#M13647</link>
      <description>&lt;P&gt;Correct.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 13:08:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/UDP-data-input/m-p/677554#M13647</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-02-14T13:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: UDP data input</title>
      <link>https://community.splunk.com/t5/Installation/UDP-data-input/m-p/677566#M13649</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259214"&gt;@jmrubio&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you mainly have to create an index on the indexers.&lt;/P&gt;&lt;P&gt;Then, if you like but itisn't mandatory, you can also create an index on the HF, but only to have the index in the dropdowns, this index will never be used.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 14:55:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/UDP-data-input/m-p/677566#M13649</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-02-14T14:55:28Z</dc:date>
    </item>
  </channel>
</rss>

