<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forward data to HF in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Forward-data-to-HF/m-p/545842#M10370</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232479"&gt;@novotxms&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand: are you asking help on how to configure the syslog source or what else?&lt;/P&gt;&lt;P&gt;If this is your need, it depends on the the source appliance: you have to go in the management interface and change the syslog destination IP.&lt;/P&gt;&lt;P&gt;Obviously, remember to configure the HF to receive syslogs on a predefined port and protocol.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 29 Mar 2021 11:12:45 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-03-29T11:12:45Z</dc:date>
    <item>
      <title>Forward data to HF</title>
      <link>https://community.splunk.com/t5/Alerting/Forward-data-to-HF/m-p/545841#M10369</link>
      <description>&lt;P&gt;I have a UF installed on syslog server and now I want the data to come to HF and not to go to UF. I just need the syslog data to be completely redirected to HF from UF. What are the config changes that I need to do?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 11:07:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Forward-data-to-HF/m-p/545841#M10369</guid>
      <dc:creator>novotxms</dc:creator>
      <dc:date>2021-03-29T11:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Forward data to HF</title>
      <link>https://community.splunk.com/t5/Alerting/Forward-data-to-HF/m-p/545842#M10370</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232479"&gt;@novotxms&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand: are you asking help on how to configure the syslog source or what else?&lt;/P&gt;&lt;P&gt;If this is your need, it depends on the the source appliance: you have to go in the management interface and change the syslog destination IP.&lt;/P&gt;&lt;P&gt;Obviously, remember to configure the HF to receive syslogs on a predefined port and protocol.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 11:12:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Forward-data-to-HF/m-p/545842#M10370</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-29T11:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: Forward data to HF</title>
      <link>https://community.splunk.com/t5/Alerting/Forward-data-to-HF/m-p/545844#M10371</link>
      <description>&lt;P&gt;I do not have access to syslog server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just have access to HF and not even to splunk indexer which is the UF. Yes I am asking help on the configuration changes that I should do&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 11:21:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Forward-data-to-HF/m-p/545844#M10371</guid>
      <dc:creator>novotxms</dc:creator>
      <dc:date>2021-03-29T11:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: Forward data to HF</title>
      <link>https://community.splunk.com/t5/Alerting/Forward-data-to-HF/m-p/545850#M10372</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232479"&gt;@novotxms&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;sorry, but there's something that I don't understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you have one or more applicances that are sending syslogs to a syslog server (syslog-ng probably);&lt;/LI&gt;&lt;LI&gt;on this server you installed an UF that reads the file written by the syslog-ng;&lt;/LI&gt;&lt;LI&gt;UF sends logs to an indexer;&lt;/LI&gt;&lt;LI&gt;now you want to receive syslogs on an HF instead of the UF;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Is it correct?&lt;/P&gt;&lt;P&gt;It's not clear for me when you say: "&lt;SPAN&gt;splunk indexer which is the UF", Indexer and UF usually are two different systems!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anyway, if you want to receive syslogs on the HF instead of the UF, you have to do the following steps:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;install Splunk on HF (it's a full Splunk installation where logs are forwarded to one or more Indexers);&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;configure it to send logs to Indexers [Settings -- Forward and Receive Data -- Forward Data];&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;enter in the management console of your appliances and modify the syslog destination (I cannot help you about this because it depends on the appliance);&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;configure on HF the receiving&amp;nbsp; on the same port/protocol of the appliance [Settings -- inputs -- Network Inputs];&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;check on Indexers if you're indexing logs.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 12:25:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Forward-data-to-HF/m-p/545850#M10372</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-29T12:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: Forward data to HF</title>
      <link>https://community.splunk.com/t5/Alerting/Forward-data-to-HF/m-p/545954#M10375</link>
      <description>&lt;P&gt;This helped me.. Thanks a lot for your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 06:14:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Forward-data-to-HF/m-p/545954#M10375</guid>
      <dc:creator>novotxms</dc:creator>
      <dc:date>2021-03-30T06:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: Forward data to HF</title>
      <link>https://community.splunk.com/t5/Alerting/Forward-data-to-HF/m-p/545961#M10376</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232479"&gt;@novotxms&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if this answer solves your need, please accept it for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 06:43:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Forward-data-to-HF/m-p/545961#M10376</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-30T06:43:08Z</dc:date>
    </item>
  </channel>
</rss>

