Getting Data In

Can someone explain splunk overview for data forwarding and parsing?

chaseto
Explorer

Hello Experts,
I am new to splunk and learning it.

http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/Routeandfilterdatad

I have read the above document in splunk regarding routing and filtering of data ,Can someone please explain with an example in detail how the parsing,filtering and configure routing(configuration files) is done if possible..

Thanks in advanace

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi chaseto, could you please explain a bit more what is not clear to you? Because the docs you linked include examples and detailed steps how to configure parsing, filtering ( http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/Routeandfilterdatad#Filter_and_route_ev... ) and routing ( http://docs.splunk.com/Documentation/Splunk/6.2.1/Forwarding/Routeandfilterdatad#Configure_routing )

chaseto
Explorer

I just want to know the overall flow start from uf to indexer with example so that i get a clear idea ,i am stuck near the conf files and how the data from log files is connected

0 Karma

Umesh_Vedicsoft
Path Finder

hello chaseto
here already somebody given the answer for it.so check it once.it may useful for you
https://answers.splunk.com/answers/352888/how-to-configure-the-splunk-universal-forwarder-an.html

0 Karma

MuS
SplunkTrust
SplunkTrust

On the UF you did set a sourcetype for the log in inputs.conf - did you? Use this sourcetype in your props.conf on the indexer and reference a stanza from transforms.conf , as well on the indexer. Restart Splunk after the changes to the conf files and any new data flowing in should be filtered and routed. If not provide all conf files please.

Hope this helps ...

cheers, MuS

0 Karma

chaseto
Explorer

thanks Mus

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...