<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Send Windows Logs to thrid party without Splunk adding in new syslog header in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Send-Windows-Logs-to-thrid-party-without-Splunk-adding-in-new/m-p/424740#M173397</link>
    <description>&lt;P&gt;I can send a subset of windows data as syslog server by sourcetype and then use the TransFroms to REGEX out the host.&lt;/P&gt;

&lt;P&gt;None of this works though if Splunk puts a timestamp server header on each syslog message. &lt;/P&gt;

&lt;P&gt;I have tried the &lt;/P&gt;

&lt;P&gt;syslogSourceType = sourcetype::WinEventLog:Security, but this doesn't work.&lt;/P&gt;

&lt;P&gt;Am I missing anything?&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jan 2019 14:56:18 GMT</pubDate>
    <dc:creator>jmcclure</dc:creator>
    <dc:date>2019-01-25T14:56:18Z</dc:date>
    <item>
      <title>Send Windows Logs to thrid party without Splunk adding in new syslog header</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Send-Windows-Logs-to-thrid-party-without-Splunk-adding-in-new/m-p/424740#M173397</link>
      <description>&lt;P&gt;I can send a subset of windows data as syslog server by sourcetype and then use the TransFroms to REGEX out the host.&lt;/P&gt;

&lt;P&gt;None of this works though if Splunk puts a timestamp server header on each syslog message. &lt;/P&gt;

&lt;P&gt;I have tried the &lt;/P&gt;

&lt;P&gt;syslogSourceType = sourcetype::WinEventLog:Security, but this doesn't work.&lt;/P&gt;

&lt;P&gt;Am I missing anything?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2019 14:56:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Send-Windows-Logs-to-thrid-party-without-Splunk-adding-in-new/m-p/424740#M173397</guid>
      <dc:creator>jmcclure</dc:creator>
      <dc:date>2019-01-25T14:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: Send Windows Logs to thrid party without Splunk adding in new syslog header</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Send-Windows-Logs-to-thrid-party-without-Splunk-adding-in-new/m-p/424741#M173398</link>
      <description>&lt;P&gt;You can try using sendCookedData=false as in &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Forwarding/Forwarddatatothird-partysystemsd#Forward_a_subset_of_data"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/Forwarding/Forwarddatatothird-partysystemsd#Forward_a_subset_of_data&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Sat, 26 Jan 2019 03:37:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Send-Windows-Logs-to-thrid-party-without-Splunk-adding-in-new/m-p/424741#M173398</guid>
      <dc:creator>davpx</dc:creator>
      <dc:date>2019-01-26T03:37:39Z</dc:date>
    </item>
  </channel>
</rss>

