<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does Splunk support LEEF formatted events? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-support-LEEF-formatted-events/m-p/77150#M15786</link>
    <description>&lt;P&gt;I couldn't find a lot of details related to LEEF, Log Event Enhanced Format.  I can speak to this question in a more general sense.  With respect to getting data in, if LEEF is truly a format and information is still collected via log file or network input (syslog) then collection can be done with Splunk with little to no effort.  If LEEF specifies proprietary methods for data collection (i.e. OPSEC) then Splunk can still satisfy data collection using a scripted input (typically a python script responsible for the collection).&lt;/P&gt;

&lt;P&gt;Once ASCII data is indexed via Splunk we can apply "late binding knowldege" (eventtypes/tags, props/transforms) at search time.  The LEEF specification should detail the format in which events are written including date/time format, delimiters, etc.  We should be able to map these details into search time properties relatively easily.&lt;/P&gt;

&lt;P&gt;So in short I would have to say Yes Splunk does.&lt;/P&gt;</description>
    <pubDate>Fri, 15 Apr 2011 20:15:22 GMT</pubDate>
    <dc:creator>hazekamp</dc:creator>
    <dc:date>2011-04-15T20:15:22Z</dc:date>
    <item>
      <title>Does Splunk support LEEF formatted events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-support-LEEF-formatted-events/m-p/77149#M15785</link>
      <description>&lt;P&gt;Does it support LEEF, Log Event Enhanced Format?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2011 03:30:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-support-LEEF-formatted-events/m-p/77149#M15785</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2011-04-08T03:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk support LEEF formatted events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-support-LEEF-formatted-events/m-p/77150#M15786</link>
      <description>&lt;P&gt;I couldn't find a lot of details related to LEEF, Log Event Enhanced Format.  I can speak to this question in a more general sense.  With respect to getting data in, if LEEF is truly a format and information is still collected via log file or network input (syslog) then collection can be done with Splunk with little to no effort.  If LEEF specifies proprietary methods for data collection (i.e. OPSEC) then Splunk can still satisfy data collection using a scripted input (typically a python script responsible for the collection).&lt;/P&gt;

&lt;P&gt;Once ASCII data is indexed via Splunk we can apply "late binding knowldege" (eventtypes/tags, props/transforms) at search time.  The LEEF specification should detail the format in which events are written including date/time format, delimiters, etc.  We should be able to map these details into search time properties relatively easily.&lt;/P&gt;

&lt;P&gt;So in short I would have to say Yes Splunk does.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2011 20:15:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-support-LEEF-formatted-events/m-p/77150#M15786</guid>
      <dc:creator>hazekamp</dc:creator>
      <dc:date>2011-04-15T20:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: Does Splunk support LEEF formatted events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-support-LEEF-formatted-events/m-p/77151#M15787</link>
      <description>&lt;P&gt;See &lt;A href="https://answers.splunk.com/answers/507704/does-splunk-recognize-leef-formatted.html"&gt;https://answers.splunk.com/answers/507704/does-splunk-recognize-leef-formatted.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 09:16:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Does-Splunk-support-LEEF-formatted-events/m-p/77151#M15787</guid>
      <dc:creator>Rob_van_Hoboken</dc:creator>
      <dc:date>2018-07-26T09:16:15Z</dc:date>
    </item>
  </channel>
</rss>

