<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Newbie soure type question (SLF4J) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Newbie-soure-type-question-SLF4J/m-p/256434#M49262</link>
    <description>&lt;P&gt;Logs generated through both log4j and slf4j usually are custom application logs, so I'd recommend creating a custom sourcetype per application log or group of similarly structured logs. There you'd configure timestamps, event breaking, field extraction, and so on.&lt;/P&gt;</description>
    <pubDate>Mon, 21 Mar 2016 21:26:34 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2016-03-21T21:26:34Z</dc:date>
    <item>
      <title>Newbie soure type question (SLF4J)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Newbie-soure-type-question-SLF4J/m-p/256433#M49261</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We are importing a file that is in SLF4J into Splunk (cloud version).  Is the log4j source type equivalent?  Or is there another source type we should use or...  is there something we need to add to Splunk?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2016 19:49:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Newbie-soure-type-question-SLF4J/m-p/256433#M49261</guid>
      <dc:creator>dbcase</dc:creator>
      <dc:date>2016-03-21T19:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie soure type question (SLF4J)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Newbie-soure-type-question-SLF4J/m-p/256434#M49262</link>
      <description>&lt;P&gt;Logs generated through both log4j and slf4j usually are custom application logs, so I'd recommend creating a custom sourcetype per application log or group of similarly structured logs. There you'd configure timestamps, event breaking, field extraction, and so on.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2016 21:26:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Newbie-soure-type-question-SLF4J/m-p/256434#M49262</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-03-21T21:26:34Z</dc:date>
    </item>
  </channel>
</rss>

