Hi,
a little bit late but...
As far as I understand putSplunk is sending data just using TCP or UDP inputs.
So... this should do the trick on Splunk UFW side...
http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports
Remember, that if you want to send different type of data please use different ports and define index and sourcetype in your inputs.conf.
Much better is using Splunk HTTP Event Collector ...
I think it's "AttributeToJSON" then?
HTH,
Holger
... View more