Getting Data In

Heavy forwarder and third-party system problem


i have faced problem with Qradar and transformation of log (Trend micro)


i forwarded the log as a raw format from splunk HF to Qradar 


i'm facing problem with the header of the events on Qradar they have double hostname and timestamp (date)

i tried to define syslogSourcetype = sourcetype::<sourcetype> 


but same occuers they are double 


is there a way to solve this problem please i'm trying now for 1 week to solve this issue



Labels (2)
0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...