Splunk Cloud Platform

splunk Universal forwarder

iherb_0718
Path Finder

Is the data that is sent from a splunk Universal Forwarder to the heavy forwarder, syslog messages?  If so, how do I find out which format it is using (ie: syslog-ng)

Labels (1)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

Hi @iherb_0718,

Splunk instances data communication is called S2S (Splunk to Splunk) are proprietary TCP communications. They are not syslog. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @iherb_0718,

Splunk instances data communication is called S2S (Splunk to Splunk) are proprietary TCP communications. They are not syslog. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...