Getting Data In

How can I change splunk default parser and use my own way of re-arranging data?

MarcHelou
New Member

let's say i have a file that I would like to input it to splunk.
but I want to have a better parser, a smarter one. how can I change the way splunk handles the incoming streams, not just taking each line by its own but applying my own code on how to arrange streams of data.

0 Karma

woodcock
Esteemed Legend

File a P1 Enhancement Request (there already is one for this).

0 Karma

MarcHelou
New Member

can you be more specific please?
Do you mean the support programs?
in other ways what I am trying to look for is a way to change the parser in splunk, so splitting income data happens in a different way than what splunk offers

0 Karma

davebrooking
Contributor

Can you provide some examples of how the data may appear in the original file, and how that data should then be indexed by Splunk?

0 Karma

micahkemp
Champion

Have you looked into Modular Inputs?

0 Karma

MarcHelou
New Member

Yes but I want to try and change how splunk arranges tuples from incoming streams and not only post each line as an event, for anonymity purposes. I want to specify how it cuts the incoming data into event and how to index them depending on several factors

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...