<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is linemerging not working with Http Event Collector (HEC)? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linemerging-not-working-with-Http-Event-Collector-HEC/m-p/459712#M79377</link>
    <description>&lt;P&gt;Doesn't using the raw endpoint solve your problem?  Can you just use that or does some other issue arise?&lt;/P&gt;</description>
    <pubDate>Wed, 07 Nov 2018 18:09:41 GMT</pubDate>
    <dc:creator>marycordova</dc:creator>
    <dc:date>2018-11-07T18:09:41Z</dc:date>
    <item>
      <title>Why is linemerging not working with Http Event Collector (HEC)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linemerging-not-working-with-Http-Event-Collector-HEC/m-p/459709#M79374</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;

&lt;P&gt;We're trying to use Splunk HEC (+fluentd) and our existing linemerge rules aren't applied to events pushed using HEC.&lt;BR /&gt;
We have a Splunk forwarder that pushes the same data and the linemerge rules properly applied to them.&lt;/P&gt;

&lt;P&gt;Am I missing anything? Does HEC ignore merge rules ?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Nov 2018 13:52:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linemerging-not-working-with-Http-Event-Collector-HEC/m-p/459709#M79374</guid>
      <dc:creator>yarinm</dc:creator>
      <dc:date>2018-11-06T13:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why is linemerging not working with Http Event Collector (HEC)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linemerging-not-working-with-Http-Event-Collector-HEC/m-p/459710#M79375</link>
      <description>&lt;P&gt;Are you sending JSON data or "raw" data?  I have JSON data that is a little off, so it uses the raw endpoint instead and I set the KV_MODE to json in props.conf.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.0/Data/FormateventsforHTTPEventCollector#Event_parsing"&gt;http://docs.splunk.com/Documentation/Splunk/7.2.0/Data/FormateventsforHTTPEventCollector#Event_parsing&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.0/RESTREF/RESTinput#services.2Fcollector.2Fraw"&gt;http://docs.splunk.com/Documentation/Splunk/7.2.0/RESTREF/RESTinput#services.2Fcollector.2Fraw&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Also...there are some things you cannot do on a Universal Forwarder that you can on a Heavy Forwarder regarding props and transforms.  &lt;/P&gt;

&lt;P&gt;So: &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;maybe try a Heavy Forwarder&lt;/LI&gt;
&lt;LI&gt;maybe try the raw HEC and a combination of props settings (also on a Heavy Forwarder?)&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 06 Nov 2018 19:42:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linemerging-not-working-with-Http-Event-Collector-HEC/m-p/459710#M79375</guid>
      <dc:creator>marycordova</dc:creator>
      <dc:date>2018-11-06T19:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why is linemerging not working with Http Event Collector (HEC)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linemerging-not-working-with-Http-Event-Collector-HEC/m-p/459711#M79376</link>
      <description>&lt;P&gt;@marycordovacaa The current official plugin by splunk for fluentd doesn't support the raw API &lt;A href="https://github.com/splunk/fluent-plugin-splunk-hec"&gt;https://github.com/splunk/fluent-plugin-splunk-hec&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;We're currently sending using the /event endpoint. &lt;/P&gt;

&lt;P&gt;After some testing, if I use the raw endpoint (and batch the events) together the LINEMERGE rule applies. If I use the  event endpoint (with batching) it ignores it completely. I was afraid that I'll have to resort to merging the lines with fluentd..&lt;/P&gt;

&lt;P&gt;Any other suggestions? &lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 07:33:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linemerging-not-working-with-Http-Event-Collector-HEC/m-p/459711#M79376</guid>
      <dc:creator>yarinm</dc:creator>
      <dc:date>2018-11-07T07:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why is linemerging not working with Http Event Collector (HEC)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linemerging-not-working-with-Http-Event-Collector-HEC/m-p/459712#M79377</link>
      <description>&lt;P&gt;Doesn't using the raw endpoint solve your problem?  Can you just use that or does some other issue arise?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 18:09:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linemerging-not-working-with-Http-Event-Collector-HEC/m-p/459712#M79377</guid>
      <dc:creator>marycordova</dc:creator>
      <dc:date>2018-11-07T18:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why is linemerging not working with Http Event Collector (HEC)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linemerging-not-working-with-Http-Event-Collector-HEC/m-p/459713#M79378</link>
      <description>&lt;P&gt;The official splunk-hec fluentd plugin doesn't support the /raw endpoint at the moment.. &lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 20:56:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linemerging-not-working-with-Http-Event-Collector-HEC/m-p/459713#M79378</guid>
      <dc:creator>yarinm</dc:creator>
      <dc:date>2018-11-07T20:56:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why is linemerging not working with Http Event Collector (HEC)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linemerging-not-working-with-Http-Event-Collector-HEC/m-p/459714#M79379</link>
      <description>&lt;P&gt;maybe submit a feature request or a bug...i dont know if its trivial to edit the plugin to use the raw endpoint or not...and then of course updates could be likely to break the customization&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 00:30:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linemerging-not-working-with-Http-Event-Collector-HEC/m-p/459714#M79379</guid>
      <dc:creator>marycordova</dc:creator>
      <dc:date>2018-11-08T00:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why is linemerging not working with Http Event Collector (HEC)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-linemerging-not-working-with-Http-Event-Collector-HEC/m-p/459715#M79380</link>
      <description>&lt;P&gt;does anyone fix this issue?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 08:19:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-linemerging-not-working-with-Http-Event-Collector-HEC/m-p/459715#M79380</guid>
      <dc:creator>benazir</dc:creator>
      <dc:date>2019-09-18T08:19:18Z</dc:date>
    </item>
  </channel>
</rss>

