<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to use the universal forwarder to parse log  files with a key value pair format and forward to splunk cloud in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-use-the-universal-forwarder-to-parse-log-files-with-a-key/m-p/425984#M74657</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm trying to parse log entries that look like so &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;EventTime=2018-12-07 10:06:31,Hostname=WIN-UE7JIIAK3IG.nxlog.co,Keywords=36028797018963968,EventType=INFO,SeverityValue=2,Severity=INFO,EventID=1,SourceName='My Script',TaskValue=1,RecordNumber=3169,ExecutionProcessID=0,ExecutionThreadID=0,Channel=Application,Message='This is a test message 1.',Opcode=Info,EventData='&amp;lt;Data&amp;gt;This is a test message 1.&amp;lt;/Data&amp;gt;',EventReceivedTime=2018-11-26 14:16:31,SourceModuleName=filein,SourceModuleType=mymodulelog,
EventTime=2018-12-07 10:16:33,Hostname=WIN-UE7JIIAK3IG.nxlog.co,Keywords=36028797018963968,EventType=INFO,SeverityValue=2,Severity=INFO,EventID=1,SourceName='My Script',TaskValue=1,RecordNumber=3170,ExecutionProcessID=0,ExecutionThreadID=0,Channel=Application,Message='This is a test message 2.',Opcode=Info,EventData='&amp;lt;Data&amp;gt;This is a test message 2.&amp;lt;/Data&amp;gt;',EventReceivedTime=2018-11-26 14:16:33,SourceModuleName=filein,SourceModuleType=mymodulelog,
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I'd like to forward these to my indexer on the Splunk cloud, and be searchable via field names. Something that is not clear to me is how I configure my inputs.conf and props.conf to handle such data.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Dec 2018 10:53:33 GMT</pubDate>
    <dc:creator>cameronharris6</dc:creator>
    <dc:date>2018-12-07T10:53:33Z</dc:date>
    <item>
      <title>How to use the universal forwarder to parse log  files with a key value pair format and forward to splunk cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-use-the-universal-forwarder-to-parse-log-files-with-a-key/m-p/425984#M74657</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm trying to parse log entries that look like so &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;EventTime=2018-12-07 10:06:31,Hostname=WIN-UE7JIIAK3IG.nxlog.co,Keywords=36028797018963968,EventType=INFO,SeverityValue=2,Severity=INFO,EventID=1,SourceName='My Script',TaskValue=1,RecordNumber=3169,ExecutionProcessID=0,ExecutionThreadID=0,Channel=Application,Message='This is a test message 1.',Opcode=Info,EventData='&amp;lt;Data&amp;gt;This is a test message 1.&amp;lt;/Data&amp;gt;',EventReceivedTime=2018-11-26 14:16:31,SourceModuleName=filein,SourceModuleType=mymodulelog,
EventTime=2018-12-07 10:16:33,Hostname=WIN-UE7JIIAK3IG.nxlog.co,Keywords=36028797018963968,EventType=INFO,SeverityValue=2,Severity=INFO,EventID=1,SourceName='My Script',TaskValue=1,RecordNumber=3170,ExecutionProcessID=0,ExecutionThreadID=0,Channel=Application,Message='This is a test message 2.',Opcode=Info,EventData='&amp;lt;Data&amp;gt;This is a test message 2.&amp;lt;/Data&amp;gt;',EventReceivedTime=2018-11-26 14:16:33,SourceModuleName=filein,SourceModuleType=mymodulelog,
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I'd like to forward these to my indexer on the Splunk cloud, and be searchable via field names. Something that is not clear to me is how I configure my inputs.conf and props.conf to handle such data.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2018 10:53:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-use-the-universal-forwarder-to-parse-log-files-with-a-key/m-p/425984#M74657</guid>
      <dc:creator>cameronharris6</dc:creator>
      <dc:date>2018-12-07T10:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to use the universal forwarder to parse log  files with a key value pair format and forward to splunk cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-use-the-universal-forwarder-to-parse-log-files-with-a-key/m-p/425985#M74658</link>
      <description>&lt;P&gt;Universal forwarders do not parse data.  That's done by indexers and heavy forwarders (that is not to imply you should replace a UF with a HF).&lt;/P&gt;

&lt;P&gt;Inputs.conf goes on the UF.  Props.conf goes on the indexer.&lt;/P&gt;

&lt;P&gt;See &lt;A href="https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F"&gt;https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Dec 2018 12:53:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-use-the-universal-forwarder-to-parse-log-files-with-a-key/m-p/425985#M74658</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-12-07T12:53:21Z</dc:date>
    </item>
  </channel>
</rss>

