All Apps and Add-ons

Splunk Add-on for Unix and Linux: Why are syslogs from Linux servers being returned as raw events?

sabaKhadivi
Path Finder

As I installed linux TA and app , received logs are in the form of raw event and they aren't indexed with this TA.
Linux servers send logs to universal forwarder by syslog, and when i search in the related index, logs seem to be raw events, and field extraction hasn't happened.

The TA is most downloaded in Splunkbase. What is the solution?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Splunk TA for Linux does not expect events to arrive via syslog. Events sent via syslog are in a very different format for which you will have to craft your own props.conf settings.

---
If this reply helps you, Karma would be appreciated.

renjith_nair
Legend

@sabaKhadivi,

Splunk TA for linux contains a set of scripted inputs to collect system information such as cpu,memory,process etc from the system.

Are you looking for RFC5424 Syslog ?

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Laser Bananas and Edge Hubs: Exploring Operational Technology (OT) Data Through a ...

  OT is a different environment to traditional IT and can have interesting challenges when interfacing the ...

Event Series: Mastering AI Tokenomics and Splunk Agent Observability

Beyond the Black Box: Correlating AI Performance and Tokenomics with Splunk Agent Observability   As ...