Getting Data In

HEC event formatting: How to configure Splunk to show only message field and not all fields?

redg
Loves-to-Learn

Good evening,
With a Java Spring Boot application, I use the library provided by Splunk to send to Splunk the logs using
com.splunk.logging.HttpEventCollectorLogbackAppender.

By default when I do a search in Splunk, the event appears like this (see image below).

redg_0-1673231701551.png

But I'd rather default the search to return results in this form.

redg_1-1673231784318.png

Is it possible to configure Splunk (Source types, etc..)  to display only the message field and not the entire event with all the fields?

 

 

 

Labels (1)
Tags (2)
0 Karma

PaulPanther
Motivator

@redg You could use the HEC Raw-Endpoint (Format events for HTTP Event Collector - Splunk Documentation) and parse & transform the events as needed.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...