<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I omit the timestamp and host that splunk automatically add to my logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-omit-the-timestamp-and-host-that-splunk-automatically/m-p/36534#M6689</link>
    <description>&lt;P&gt;hi guys,&lt;BR /&gt;
I've added my first logs in splunk today. I notice that in the beginning of each row splunk has added a prefix of timestamp and host. For example this is a single log line(refer to the bold text):&lt;/P&gt;

&lt;P&gt;&lt;FONT color="red"&gt;&lt;I&gt;&lt;B&gt;Jun 29 16:16:44 127.0.0.1&lt;/B&gt;&lt;/I&gt;&lt;/FONT&gt; 2011-06-29 16:16:44.067 [main           ] INFO  com.cloudon.VabConnector  - About to activate VabConnector with parameters node id [1], ZK_connect_str[127.0.0.1:2181], VabConnectionServerPort[8000], ownIp[10.0.0.8]&lt;/P&gt;

&lt;P&gt;I've configured my channel in the web interface in - Home » Add Data » UDP » Add New&lt;BR /&gt;&lt;BR /&gt;
I've defined it as syslog source type and I'm sending the logs from my application. I've used wireshark to verify that the message I send is without the prefix.&lt;/P&gt;

&lt;P&gt;Do you know why splunk add this prefix?&lt;BR /&gt;&lt;BR /&gt;
More importantly, I can I remove it from the logs?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
  Eldad.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 09:42:39 GMT</pubDate>
    <dc:creator>dadi</dc:creator>
    <dc:date>2020-09-28T09:42:39Z</dc:date>
    <item>
      <title>How can I omit the timestamp and host that splunk automatically add to my logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-omit-the-timestamp-and-host-that-splunk-automatically/m-p/36534#M6689</link>
      <description>&lt;P&gt;hi guys,&lt;BR /&gt;
I've added my first logs in splunk today. I notice that in the beginning of each row splunk has added a prefix of timestamp and host. For example this is a single log line(refer to the bold text):&lt;/P&gt;

&lt;P&gt;&lt;FONT color="red"&gt;&lt;I&gt;&lt;B&gt;Jun 29 16:16:44 127.0.0.1&lt;/B&gt;&lt;/I&gt;&lt;/FONT&gt; 2011-06-29 16:16:44.067 [main           ] INFO  com.cloudon.VabConnector  - About to activate VabConnector with parameters node id [1], ZK_connect_str[127.0.0.1:2181], VabConnectionServerPort[8000], ownIp[10.0.0.8]&lt;/P&gt;

&lt;P&gt;I've configured my channel in the web interface in - Home » Add Data » UDP » Add New&lt;BR /&gt;&lt;BR /&gt;
I've defined it as syslog source type and I'm sending the logs from my application. I've used wireshark to verify that the message I send is without the prefix.&lt;/P&gt;

&lt;P&gt;Do you know why splunk add this prefix?&lt;BR /&gt;&lt;BR /&gt;
More importantly, I can I remove it from the logs?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
  Eldad.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:42:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-omit-the-timestamp-and-host-that-splunk-automatically/m-p/36534#M6689</guid>
      <dc:creator>dadi</dc:creator>
      <dc:date>2020-09-28T09:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: How can I omit the timestamp and host that splunk automatically add to my logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-omit-the-timestamp-and-host-that-splunk-automatically/m-p/36535#M6690</link>
      <description>&lt;P&gt;I found the answer in &lt;A href="http://splunk-base.splunk.com/answers/9484/why-are-a-timestamp-and-hostname-prepended-to-my-udp-input-events"&gt;here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2011 08:39:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-omit-the-timestamp-and-host-that-splunk-automatically/m-p/36535#M6690</guid>
      <dc:creator>dadi</dc:creator>
      <dc:date>2011-06-30T08:39:57Z</dc:date>
    </item>
  </channel>
</rss>

