Refine your search:

hi universalforwarder receives and send the syslog data to do? If possible, how do?

asked 12 Apr '12, 06:15

khyoung7410's gravatar image

khyoung7410
2719
accept rate: 0%

edited 12 Apr '12, 06:18


One Answer:

Yes, it is possible. You need to configure your UF to listen on a network port and receive syslog data. You can then forward the data to an indexer where it'll be written to disk.

The instructions for this can be found in the documentation here:

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Setupforwardingandreceiving

link

answered 12 Apr '12, 07:31

jbsplunk's gravatar image

jbsplunk ♦
11.1k1625
accept rate: 49%

Thank you. I will try it

(12 Apr '12, 19:28) khyoung7410
Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×307
×285

Asked: 12 Apr '12, 06:15

Seen: 653 times

Last updated: 12 Apr '12, 19:28

Copyright © 2005-2012 Splunk Inc. All rights reserved.