Getting Data In

For UDP inputs, does the raw log priority factor into LINE_BREAKER?

twinspop
Influencer

If you watch the wire data via tcpdump, you will see syslog events contain the log priority at the beginning of an event:

<134>12/1/14 10:02:03.123 INFO some log info

When defining LINE_BREAKER for this log, do I need to factor in the priority, or is that stripped before that stage?

0 Karma
1 Solution

twinspop
Influencer

Based on my own experiments, no, do not account for the log priority identifier in angle brackets. Pretend like it's not there.

View solution in original post

0 Karma

twinspop
Influencer

Based on my own experiments, no, do not account for the log priority identifier in angle brackets. Pretend like it's not there.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...