<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk data format in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-data-format/m-p/58525#M14331</link>
    <description>&lt;P&gt;What is the Splunk data format of data being forwarded? Splunk website states TCP is format for transmission but its really a protocol for transmission?&lt;/P&gt;</description>
    <pubDate>Mon, 14 Mar 2011 19:06:08 GMT</pubDate>
    <dc:creator>wildbill4</dc:creator>
    <dc:date>2011-03-14T19:06:08Z</dc:date>
    <item>
      <title>Splunk data format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-data-format/m-p/58525#M14331</link>
      <description>&lt;P&gt;What is the Splunk data format of data being forwarded? Splunk website states TCP is format for transmission but its really a protocol for transmission?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2011 19:06:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-data-format/m-p/58525#M14331</guid>
      <dc:creator>wildbill4</dc:creator>
      <dc:date>2011-03-14T19:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk data format</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-data-format/m-p/58526#M14332</link>
      <description>&lt;P&gt;The "over the wire" format for Splunk's communications between forwarders and indexers does use TCP as its transport.  The "Splunk protocol" inside TCP is Splunk proprietary and (to my knowledge) not documented.  &lt;/P&gt;

&lt;P&gt;If you are planning to build a receiver for Splunk forwarder data, be aware that Splunk can forward over a plain TCP socket to a 3rd party system.  See &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Forwarddatatothird-partysystems" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Admin/Forwarddatatothird-partysystems&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2011 22:25:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-data-format/m-p/58526#M14332</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2011-03-14T22:25:09Z</dc:date>
    </item>
  </channel>
</rss>

