All Apps and Add-ons

Splunk Add-on for Unix and Linux: Why are syslogs from Linux servers being returned as raw events?

Path Finder

As I installed linux TA and app , received logs are in the form of raw event and they aren't indexed with this TA.
Linux servers send logs to universal forwarder by syslog, and when i search in the related index, logs seem to be raw events, and field extraction hasn't happened.

The TA is most downloaded in Splunkbase. What is the solution?

0 Karma


The Splunk TA for Linux does not expect events to arrive via syslog. Events sent via syslog are in a very different format for which you will have to craft your own props.conf settings.

If this reply helps you, an upvote would be appreciated.



Splunk TA for linux contains a set of scripted inputs to collect system information such as cpu,memory,process etc from the system.

Are you looking for RFC5424 Syslog ?

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!