Getting Data In

How to let splunkforwarder transfering by UDP 514

New Member


I have the question about splunkforwarder , so hope someone can help me !

First ,
I successfully used to transfer logs , as follows

host =

disabled = 0
sourcetype = http_access_log

defaultGroup =

server =


But if i want to change to UDP 514 , i search and read documents, i cant understand how to do it correctly .

Second ,
I read the, but where to use the syntax of outputtext , command or others ?

best regards,


Tags (1)
0 Karma


I think you're confusing concepts quite a bit here. Outputtext is a command used in searches that does something else entirely.

Light and universal forwarders cannot send syslog data. More information in the syslog part of the outputs.conf documentation here:


As I said in my answer above, you can NOT use your forwarder for sending syslog data.

New Member

Another sample as follows,

defaultGroup =

server =
type = udp

I want to transfer the client's logs to server' s udp 514 port,
but the server does not receive any logs from client's.

client -------------> server:514

Can splunk be ?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...