<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexing 7-Zip Files. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-7-Zip-Files/m-p/79763#M16387</link>
    <description>&lt;P&gt;Thanks for the prompt response!  I may just end up having to stick with ZIP files, instead of 7z files then.&lt;/P&gt;

&lt;P&gt;If I were to attempt support of 7z files, where would I go to get more info on mimicking the tgz configuration/setup?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 13 Apr 2011 01:51:10 GMT</pubDate>
    <dc:creator>sthao</dc:creator>
    <dc:date>2011-04-13T01:51:10Z</dc:date>
    <item>
      <title>Indexing 7-Zip Files.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-7-Zip-Files/m-p/79761#M16385</link>
      <description>&lt;P&gt;I am using Splunk 4.2 and would like to know if .7z files can be indexed?&lt;/P&gt;

&lt;P&gt;I have attempted to index .7z files via the below steps, but have been unsuccessful:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Copying the crawl.conf file from ..\etc\system\default.&lt;/LI&gt;
&lt;LI&gt;Placing the crawl.conf file in ..\etc\system\local.&lt;/LI&gt;
&lt;LI&gt;Adding &lt;STRONG&gt;7z&lt;/STRONG&gt; to the &lt;STRONG&gt;packed_extensions_list&lt;/STRONG&gt; line.&lt;/LI&gt;
&lt;LI&gt;Restarting Splunk.&lt;/LI&gt;
&lt;LI&gt;Re-indexing the location which holds the .7z files.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Thank you for any direction that can be given!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2011 00:15:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-7-Zip-Files/m-p/79761#M16385</guid>
      <dc:creator>sthao</dc:creator>
      <dc:date>2011-04-13T00:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: Indexing 7-Zip Files.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-7-Zip-Files/m-p/79762#M16386</link>
      <description>&lt;P&gt;No. Splunk has configurations for gzip, bz2, and compress files, among others, but not 7z. You could probably add support for that if you choose and install a command-line decompressor with streaming decompression by mimicking the configuration for tgz files.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2011 01:15:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-7-Zip-Files/m-p/79762#M16386</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-04-13T01:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: Indexing 7-Zip Files.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexing-7-Zip-Files/m-p/79763#M16387</link>
      <description>&lt;P&gt;Thanks for the prompt response!  I may just end up having to stick with ZIP files, instead of 7z files then.&lt;/P&gt;

&lt;P&gt;If I were to attempt support of 7z files, where would I go to get more info on mimicking the tgz configuration/setup?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2011 01:51:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexing-7-Zip-Files/m-p/79763#M16387</guid>
      <dc:creator>sthao</dc:creator>
      <dc:date>2011-04-13T01:51:10Z</dc:date>
    </item>
  </channel>
</rss>

