Getting Data In

Data ingest

splunkville
Observer

Monitor set to pull in a watched log that has no props/transforms configs applied. This would ingest the entire file contents, correct? 

Labels (1)
Tags (1)
0 Karma

livehybrid
Ultra Champion

Hi @splunkville 

The default configurations for a sourcetype can often be "good enough" for some logs, Splunk does a good job at determining timestamp extraction but if your logs contain multi-line events, long lines (>10000 chars),multiple timestamps or anything like this then it might struggle or you might get mixed results.

Its also worth noting that from a performance perspective its best to tweak these settings and incorporate the "Great 8" (See https://lantern.splunk.com/Splunk_Platform/Product_Tips/Data_Management/Configuring_new_source_types) to ensure accuracy but also to improve performance of the data being ingested.

:glowing_star: Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @splunkville ,

yes, in general, if you configure a monitor you read the file, but what's your issue and you question?

Are you working on a Universal Forwarder or a stand alone Splunk server or what else?

Please, share more datails about your issue.

Ciao.

Giuseppe

0 Karma

splunkville
Observer

Since no configs are telling splunk how to parse the data, it will pull in / read the entire contents of the file by default. That is my understanding.

This monitor is set in a config file pushed to the uf. All I'm doing is telling splunk to go get that log. Not concerned with formatting / parsing right now. Is there anything that will stop / limit this incoming data?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @splunkville ,

yes it is correct, but what's your issue?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

The Payment Operations Wake-Up Call: Why Financial Institutions Can't Afford ...

The same scenario plays out across financial institutions daily. A payment system fails at 11:30 AM on a busy ...

Make Your Case: A Ready-to-Send Letter for Getting Approval to Attend .conf25

Hello Splunkers, Want to attend .conf25 in Boston this year but not sure how to convince your manager? We've ...

Community Spotlight: A Splunk Expert's Journey

In the world of data analytics, some journeys leave a lasting impact not only on the individual but on the ...