<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I send journald logs to my Splunk indexer? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-journald-logs-to-my-Splunk-indexer/m-p/259659#M49840</link>
    <description>&lt;P&gt;Since splunk can't read the default binary format of journal , you should write to a text file and then forward (don't remember but read it somewhere)&lt;/P&gt;

&lt;P&gt;There is a blog which talks about this in detail for different flavors, might be useful for you . &lt;/P&gt;

&lt;P&gt;&lt;A href="http://blogs.splunk.com/2015/04/30/integrating-splunk-with-docker-coreos-and-journald/"&gt;http://blogs.splunk.com/2015/04/30/integrating-splunk-with-docker-coreos-and-journald/&lt;/A&gt; &lt;/P&gt;</description>
    <pubDate>Tue, 02 Feb 2016 06:56:38 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2016-02-02T06:56:38Z</dc:date>
    <item>
      <title>How do I send journald logs to my Splunk indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-journald-logs-to-my-Splunk-indexer/m-p/259658#M49839</link>
      <description>&lt;P&gt;I would like to separate these logs into units (ie - &lt;EM&gt;etcd.service, kube-apiserver.service, kube-controller-manager.service, etc&lt;/EM&gt;)&lt;BR /&gt;
I'd then like to send those different logs to Splunk.&lt;BR /&gt;
Do I have to force these logs to a file first, then move them?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2016 15:12:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-journald-logs-to-my-Splunk-indexer/m-p/259658#M49839</guid>
      <dc:creator>ctjd81</dc:creator>
      <dc:date>2016-02-01T15:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: How do I send journald logs to my Splunk indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-journald-logs-to-my-Splunk-indexer/m-p/259659#M49840</link>
      <description>&lt;P&gt;Since splunk can't read the default binary format of journal , you should write to a text file and then forward (don't remember but read it somewhere)&lt;/P&gt;

&lt;P&gt;There is a blog which talks about this in detail for different flavors, might be useful for you . &lt;/P&gt;

&lt;P&gt;&lt;A href="http://blogs.splunk.com/2015/04/30/integrating-splunk-with-docker-coreos-and-journald/"&gt;http://blogs.splunk.com/2015/04/30/integrating-splunk-with-docker-coreos-and-journald/&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2016 06:56:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-journald-logs-to-my-Splunk-indexer/m-p/259659#M49840</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2016-02-02T06:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do I send journald logs to my Splunk indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-journald-logs-to-my-Splunk-indexer/m-p/259660#M49841</link>
      <description>&lt;P&gt;This got me a long way to the answer, thanks!!!&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 18:57:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-journald-logs-to-my-Splunk-indexer/m-p/259660#M49841</guid>
      <dc:creator>ctjd81</dc:creator>
      <dc:date>2016-02-03T18:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: How do I send journald logs to my Splunk indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-journald-logs-to-my-Splunk-indexer/m-p/259661#M49842</link>
      <description>&lt;P&gt;This is a terrible answer.  Splunk should put this into the TA for NIX.  expecting each customer to figure out some crap method of this is BS.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 19:42:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-journald-logs-to-my-Splunk-indexer/m-p/259661#M49842</guid>
      <dc:creator>alastor</dc:creator>
      <dc:date>2020-03-04T19:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: How do I send journald logs to my Splunk indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-journald-logs-to-my-Splunk-indexer/m-p/616394#M106502</link>
      <description>&lt;P&gt;Agreed... I'm going through these older journald posts for other reasons, but it looks like no one has updated responses here that there's better ways now? Starting in Splunk 8.1 there is native&lt;SPAN&gt;&amp;nbsp;journald input support (separate from any TA for *NIX):&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/CollecteventsfromJournalD" target="_blank" rel="nofollow noopener noreferrer"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/CollecteventsfromJournalD&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 21:58:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-send-journald-logs-to-my-Splunk-indexer/m-p/616394#M106502</guid>
      <dc:creator>tgurantz_splunk</dc:creator>
      <dc:date>2022-10-07T21:58:25Z</dc:date>
    </item>
  </channel>
</rss>

