<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UDP input and _TCP_ROUTING - is it possible? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/UDP-input-and-TCP-ROUTING-is-it-possible/m-p/44044#M179178</link>
    <description>&lt;P&gt;yes, here you are reciving data via udp but sending data via tcp and both are separated...&lt;BR /&gt;
-Kamal Bisht&lt;/P&gt;</description>
    <pubDate>Sun, 17 Mar 2013 04:01:10 GMT</pubDate>
    <dc:creator>kml_uvce</dc:creator>
    <dc:date>2013-03-17T04:01:10Z</dc:date>
    <item>
      <title>UDP input and _TCP_ROUTING - is it possible?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/UDP-input-and-TCP-ROUTING-is-it-possible/m-p/44042#M179176</link>
      <description>&lt;P&gt;Is it possible to use _TCP_ROUTING with a UDP input? I can not get it to work. My other "monitor" inputs works fine with _TCP_ROUTING. This is a full forwarder not a lwf.&lt;/P&gt;

&lt;P&gt;inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[udp://514]
index = testapp
sourcetype = syslog
_TCP_ROUTING = pnlogGroup
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;outputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = SlogGroup
disabled = false
indexAndForward = 0

[tcpout:pnlogGroup]
disabled = false
server = 10.0.0.41:9997

[tcpout:SlogGroup]
disabled = false
server = 10.0.0.50:9995
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 14 Feb 2011 21:34:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/UDP-input-and-TCP-ROUTING-is-it-possible/m-p/44042#M179176</guid>
      <dc:creator>andyk</dc:creator>
      <dc:date>2011-02-14T21:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: UDP input and _TCP_ROUTING - is it possible?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/UDP-input-and-TCP-ROUTING-is-it-possible/m-p/44043#M179177</link>
      <description>&lt;P&gt;I think you already got answer a looooooong time ago. Answer is yes. A full Forwarder process data and parse events from udp inputs, and send the processed/parsed to Splunk as you configured in outputs.conf. &lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2013 23:35:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/UDP-input-and-TCP-ROUTING-is-it-possible/m-p/44043#M179177</guid>
      <dc:creator>Masa</dc:creator>
      <dc:date>2013-03-15T23:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: UDP input and _TCP_ROUTING - is it possible?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/UDP-input-and-TCP-ROUTING-is-it-possible/m-p/44044#M179178</link>
      <description>&lt;P&gt;yes, here you are reciving data via udp but sending data via tcp and both are separated...&lt;BR /&gt;
-Kamal Bisht&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2013 04:01:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/UDP-input-and-TCP-ROUTING-is-it-possible/m-p/44044#M179178</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2013-03-17T04:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: UDP input and _TCP_ROUTING - is it possible?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/UDP-input-and-TCP-ROUTING-is-it-possible/m-p/44045#M179179</link>
      <description>&lt;P&gt;What do you mean by "sending data via tcp and both are separated.."?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2013 17:07:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/UDP-input-and-TCP-ROUTING-is-it-possible/m-p/44045#M179179</guid>
      <dc:creator>Masa</dc:creator>
      <dc:date>2013-03-18T17:07:35Z</dc:date>
    </item>
  </channel>
</rss>

