<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Decompressing log files from Microsoft Azure Blob in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Decompressing-log-files-from-Microsoft-Azure-Blob/m-p/538011#M90180</link>
    <description>&lt;P&gt;I have logs that are stored in Micrsoft Blob Storage which are compressed as .xz files, but they are not named with that extension, they are in the format: kuberenetes-&amp;lt;datetime&amp;gt; ( example: kubernetes-202101310701).&amp;nbsp; What I'm trying to do is ingest these logs into Splunk using the Microsoft Cloud Services app.&amp;nbsp; Because these files are compressed, I believe I need to run the&amp;nbsp;unarchive_cmd against it using props.conf, but I'm not sure this is even supported with this app.&amp;nbsp; I've searched high and low and have not come across any information that supports it.&amp;nbsp; As a side note, these files are kuberenetes logs coming from SAP CC2V so I do not have any control of how they are written to blob storage, I can only access them after the fact.&amp;nbsp; When I enable the application the data starts to stream in but it's all gibberish because the files are compressed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is what I get:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;A target="_blank"&gt;&lt;SPAN&gt;1/31/21&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10:32:25.000 AM&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="json-event  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;Geq��)�5xi� ��B�;X&amp;#30;�%�&amp;#24;��Ul���&amp;#31;&amp;#28;N�ioG�����X�&amp;#2;�o��47`�RK�&amp;#16;Bd�g�x&amp;#24;�A���ʪe���a�E�V�����xUS&amp;lt;x�5=�H�R&amp;#15;�4��2&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="shared-eventsviewer-shared-eventfields"&gt;Type &amp;nbsp; Field Value Actions &lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;Event&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;timestamp&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;none&lt;/A&gt;&lt;/TD&gt;&lt;TD width="40.0696px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;Time&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;_time&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;2021-01-31T10:32:25.000-08:00&lt;/TD&gt;&lt;TD width="40.0696px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;Default&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;host&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;ip-10-151-4-90&lt;/A&gt;&lt;/TD&gt;&lt;TD width="40.0696px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;test&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;punct&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;)t;%&amp;lt;=&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;source&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;kubernetes-202101311433&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sourcetype&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;mscs:storage:blob:k8&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;splunk_server&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;idx-i-&amp;lt;redacted&amp;gt;?.splunkcloud.com&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is what I'm trying...&lt;/P&gt;&lt;P&gt;input.conf:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[mscs_storage_blob://SAP S3 Logs]
disabled = 0
account = SAP S3
blob_list = kubernetes*
blob_mode = append
collection_interval = 3600
container_name = commerce-logging
sourcetype = mscs:storage:blob:k8
index = test&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;props.conf:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[source::...(.*)]
invalid_cause = archive
unarchive_cmd = /usr/bin/xz -cd -
sourcetype = mscs:storage:blob:k8
KV_MODE = json
NO_BINARY_CHECK = true

[mscs_storage_blob://SAP S3 Logs]
invalid_cause = archive
unarchive_cmd = /usr/bin/xz -cd -
sourcetype = mscs:storage:blob:k8
KV_MODE = json
NO_BINARY_CHECK = true

[mscs:storage:blob]
invalid_cause = archive
unarchive_cmd = /usr/bin/xz -cd -
sourcetype = mscs:storage:blob:k8
KV_MODE = json
NO_BINARY_CHECK = true

[mscs:storage:blob:k8]
invalid_cause = archive
unarchive_cmd = /usr/bin/xz -cd -
sourcetype = mscs:storage:blob:k8
KV_MODE = json
NO_BINARY_CHECK = true&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know the props.conf is not correct or does not need that many stanzas, but I tried adding all of these in an attempt to get it to work as I'm not even sure it's using the props.conf file.&amp;nbsp; As a side note, if I decompress the file in Azure Blob and then ingest it, it works perfectly.&amp;nbsp; So the question is, can I use the 'invalid_cause' and 'unarchive_cmd' in the props for Microsoft Cloud Services app?&amp;nbsp; If this doesn't work I need to come up with another solution, and I'm thinking I can just copy the files locally and then run it through a standard file monitor process and attempt to run the unarchive command there.&lt;/P&gt;</description>
    <pubDate>Sun, 31 Jan 2021 19:11:51 GMT</pubDate>
    <dc:creator>NickSegalle</dc:creator>
    <dc:date>2021-01-31T19:11:51Z</dc:date>
    <item>
      <title>Decompressing log files from Microsoft Azure Blob</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Decompressing-log-files-from-Microsoft-Azure-Blob/m-p/538011#M90180</link>
      <description>&lt;P&gt;I have logs that are stored in Micrsoft Blob Storage which are compressed as .xz files, but they are not named with that extension, they are in the format: kuberenetes-&amp;lt;datetime&amp;gt; ( example: kubernetes-202101310701).&amp;nbsp; What I'm trying to do is ingest these logs into Splunk using the Microsoft Cloud Services app.&amp;nbsp; Because these files are compressed, I believe I need to run the&amp;nbsp;unarchive_cmd against it using props.conf, but I'm not sure this is even supported with this app.&amp;nbsp; I've searched high and low and have not come across any information that supports it.&amp;nbsp; As a side note, these files are kuberenetes logs coming from SAP CC2V so I do not have any control of how they are written to blob storage, I can only access them after the fact.&amp;nbsp; When I enable the application the data starts to stream in but it's all gibberish because the files are compressed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is what I get:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;A target="_blank"&gt;&lt;SPAN&gt;1/31/21&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10:32:25.000 AM&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="json-event  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;Geq��)�5xi� ��B�;X&amp;#30;�%�&amp;#24;��Ul���&amp;#31;&amp;#28;N�ioG�����X�&amp;#2;�o��47`�RK�&amp;#16;Bd�g�x&amp;#24;�A���ʪe���a�E�V�����xUS&amp;lt;x�5=�H�R&amp;#15;�4��2&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="shared-eventsviewer-shared-eventfields"&gt;Type &amp;nbsp; Field Value Actions &lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;Event&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;timestamp&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;none&lt;/A&gt;&lt;/TD&gt;&lt;TD width="40.0696px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;Time&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;_time&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;2021-01-31T10:32:25.000-08:00&lt;/TD&gt;&lt;TD width="40.0696px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;Default&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;host&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;ip-10-151-4-90&lt;/A&gt;&lt;/TD&gt;&lt;TD width="40.0696px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;test&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;punct&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;)t;%&amp;lt;=&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;source&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;kubernetes-202101311433&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sourcetype&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;mscs:storage:blob:k8&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="64.2783px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD width="113.53px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;splunk_server&lt;/SPAN&gt;&lt;/A&gt;&lt;/TD&gt;&lt;TD width="265.461px" height="24px"&gt;&lt;A href="https://arbonne.splunkcloud.com/en-US/app/search/search?q=search%20index%3D*%20sourcetype%3D%22mscs%3Astorage%3Ablob%3Ak8%22&amp;amp;display.page.search.mode=verbose&amp;amp;dispatch.sample_ratio=1&amp;amp;workload_pool=standard_perf&amp;amp;earliest=rt-5m&amp;amp;latest=rt&amp;amp;sid=rt_1612116779.310199#" target="_blank" rel="noopener"&gt;idx-i-&amp;lt;redacted&amp;gt;?.splunkcloud.com&lt;/A&gt;&lt;/TD&gt;&lt;TD width="251.27px" height="24px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is what I'm trying...&lt;/P&gt;&lt;P&gt;input.conf:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[mscs_storage_blob://SAP S3 Logs]
disabled = 0
account = SAP S3
blob_list = kubernetes*
blob_mode = append
collection_interval = 3600
container_name = commerce-logging
sourcetype = mscs:storage:blob:k8
index = test&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;props.conf:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[source::...(.*)]
invalid_cause = archive
unarchive_cmd = /usr/bin/xz -cd -
sourcetype = mscs:storage:blob:k8
KV_MODE = json
NO_BINARY_CHECK = true

[mscs_storage_blob://SAP S3 Logs]
invalid_cause = archive
unarchive_cmd = /usr/bin/xz -cd -
sourcetype = mscs:storage:blob:k8
KV_MODE = json
NO_BINARY_CHECK = true

[mscs:storage:blob]
invalid_cause = archive
unarchive_cmd = /usr/bin/xz -cd -
sourcetype = mscs:storage:blob:k8
KV_MODE = json
NO_BINARY_CHECK = true

[mscs:storage:blob:k8]
invalid_cause = archive
unarchive_cmd = /usr/bin/xz -cd -
sourcetype = mscs:storage:blob:k8
KV_MODE = json
NO_BINARY_CHECK = true&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know the props.conf is not correct or does not need that many stanzas, but I tried adding all of these in an attempt to get it to work as I'm not even sure it's using the props.conf file.&amp;nbsp; As a side note, if I decompress the file in Azure Blob and then ingest it, it works perfectly.&amp;nbsp; So the question is, can I use the 'invalid_cause' and 'unarchive_cmd' in the props for Microsoft Cloud Services app?&amp;nbsp; If this doesn't work I need to come up with another solution, and I'm thinking I can just copy the files locally and then run it through a standard file monitor process and attempt to run the unarchive command there.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2021 19:11:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Decompressing-log-files-from-Microsoft-Azure-Blob/m-p/538011#M90180</guid>
      <dc:creator>NickSegalle</dc:creator>
      <dc:date>2021-01-31T19:11:51Z</dc:date>
    </item>
  </channel>
</rss>

