Getting Data In

Fields in Splunk Cloud from Heavy Forwarder (Add-on Windows and Linux)

sachaz
Explorer

I've installed Splunk Add-on for Windows and Splunk Add-on for Unix and Linux in the Heavy forwarder. I only edited inputs.conf file with the routes I want to monitor, but whit the sourcetype linux_secure and bash_history, when I check on my Splunk Cloud the are no fields like "src", "dest", etc. I'm missing something? Any ideas how to resolve this?

0 Karma

vliggio
Communicator

The src and dest field extractions take place at search time, so you have to put a ticket in and request that Splunk install the add-ons on to your Splunk Cloud environment. If you look in the Splunk_TA_nix, you'll see the props.conf has a bunch of FIELDALIAS settings, which, if you refer to https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings, you will see that FIELDALIAS is a search time configuration.

sachaz
Explorer

I'm waiting for a few days ago the splunk support response, I was in doubt if I should do something else before, thanks

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...