<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Forwarding in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100620#M182778</link>
    <description>&lt;P&gt;Following is high level flow;&lt;BR /&gt;
Splunk Forwarder -&amp;gt; Indexer -&amp;gt; Search Head&lt;/P&gt;

&lt;P&gt;Splunk requires splunk forwarder agent (Universal Forwarder / Splunk Light Forwarder / Splunk Heavy Forwarder) to forward data to the splunk indexers from the servers.&lt;BR /&gt;
eg : you forward logs (/var/log/messages) from your test_server to splunk indexer&lt;/P&gt;

&lt;P&gt;The data is forwarded on the receiving port you set on the indexers (by default it is 9997).&lt;/P&gt;

&lt;P&gt;Search Head is the central querying hub which will pull data from one or many indexers.&lt;/P&gt;

&lt;P&gt;I am not sure why you are trying to send event from splunk servers to the RHEL box, it should be other way round.&lt;/P&gt;</description>
    <pubDate>Fri, 19 Apr 2013 06:06:04 GMT</pubDate>
    <dc:creator>sinclairmachado</dc:creator>
    <dc:date>2013-04-19T06:06:04Z</dc:date>
    <item>
      <title>Splunk Forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100619#M182777</link>
      <description>&lt;P&gt;Hello, Can any one please tell me that, Whether splunk reads event from only splunk installed machine or non-splunk machine also ?&lt;BR /&gt;
Also Please give me idea about forwarding mechanism of splunk.&lt;BR /&gt;
and one more question is that, in which format splunk forwards events? whether it uses any binary format ? because when I was trying to forward events from splunk to RHEL machine it is forwarded in raw (0#) format. Is this the behavior of splunk or m I going wrong somewhere ?&lt;/P&gt;

&lt;P&gt;Thanks In Advance. &lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2013 04:35:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100619#M182777</guid>
      <dc:creator>shaileshpawar21</dc:creator>
      <dc:date>2013-04-19T04:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100620#M182778</link>
      <description>&lt;P&gt;Following is high level flow;&lt;BR /&gt;
Splunk Forwarder -&amp;gt; Indexer -&amp;gt; Search Head&lt;/P&gt;

&lt;P&gt;Splunk requires splunk forwarder agent (Universal Forwarder / Splunk Light Forwarder / Splunk Heavy Forwarder) to forward data to the splunk indexers from the servers.&lt;BR /&gt;
eg : you forward logs (/var/log/messages) from your test_server to splunk indexer&lt;/P&gt;

&lt;P&gt;The data is forwarded on the receiving port you set on the indexers (by default it is 9997).&lt;/P&gt;

&lt;P&gt;Search Head is the central querying hub which will pull data from one or many indexers.&lt;/P&gt;

&lt;P&gt;I am not sure why you are trying to send event from splunk servers to the RHEL box, it should be other way round.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2013 06:06:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100620#M182778</guid>
      <dc:creator>sinclairmachado</dc:creator>
      <dc:date>2013-04-19T06:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100621#M182779</link>
      <description>&lt;P&gt;Thanks you for your response,&lt;BR /&gt;
Actually I was trying to send events which was stored into splunk.&lt;BR /&gt;
I want to read that event in non-splunk machine.&lt;BR /&gt;
can you please help me in that?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2013 17:49:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100621#M182779</guid>
      <dc:creator>shaileshpawar21</dc:creator>
      <dc:date>2013-04-21T17:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100622#M182780</link>
      <description>&lt;P&gt;Have a look at;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Forwarddatatothird-partysystemsd"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/Deploy/Forwarddatatothird-partysystemsd&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2013 19:02:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100622#M182780</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-04-21T19:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100623#M182781</link>
      <description>&lt;P&gt;Thanks kristian,&lt;BR /&gt;
Can you please tell me whole step by step process of receiving and forwarding events.&lt;BR /&gt;
Actually I want to send RHEL events stored in splunk server to other non-splunk machine.&lt;BR /&gt;
Please help me in that.&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2013 06:37:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100623#M182781</guid>
      <dc:creator>shaileshpawar21</dc:creator>
      <dc:date>2013-04-22T06:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100624#M182782</link>
      <description>&lt;P&gt;Hi Shailesh,&lt;BR /&gt;
Apologize I did not get your question.&lt;BR /&gt;
You can also do it by using splunk scheduler or alerting mechanism.&lt;/P&gt;

&lt;P&gt;When you generate an alert a CSV file is generated at back-end with results, you can use that and scp it to the server where you want to place it by executing a script.&lt;BR /&gt;
(When setting up alerting you have an option to execute a script.)&lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Sinclair&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 14:46:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100624#M182782</guid>
      <dc:creator>sinclairmachado</dc:creator>
      <dc:date>2013-04-23T14:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100625#M182783</link>
      <description>&lt;P&gt;Thanks Sinclair,&lt;/P&gt;

&lt;P&gt;Lets consider I have 3 machines A,B and C.&lt;BR /&gt;
B is my splunk server. Now I want to receive events from machine A to splunk server B and then froward these events (which are stored in splunk server B) tothird machine C.&lt;BR /&gt;
Please help in this scenario.&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2013 09:45:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100625#M182783</guid>
      <dc:creator>shaileshpawar21</dc:creator>
      <dc:date>2013-04-24T09:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100626#M182784</link>
      <description>&lt;P&gt;1) A -&amp;gt; B&lt;BR /&gt;
This will be your normal splunk configuration that will forward data from server A to splunk server B&lt;/P&gt;

&lt;P&gt;2) B -&amp;gt; C&lt;BR /&gt;
To Send data from splunk server B to server C do the following;&lt;BR /&gt;
Create a shell script with splunk CLI search redirecting data to a data file.&lt;BR /&gt;
SCP the file to server C&lt;/P&gt;

&lt;P&gt;Example of steps in the shell will be;&lt;BR /&gt;
$SPLUNK_HOME/bin/splunk search 'index=* search string' -earliest_time='-1d' -latest_time='now' &amp;gt; datafile&lt;BR /&gt;
scp ./datafile user@server:/path/&lt;/P&gt;

&lt;P&gt;Let me know if that works for you.&lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Sinclair&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:47:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Forwarding/m-p/100626#M182784</guid>
      <dc:creator>sinclairmachado</dc:creator>
      <dc:date>2020-09-28T13:47:18Z</dc:date>
    </item>
  </channel>
</rss>

