Getting Data In

How can I change splunk default parser and use my own way of re-arranging data?

MarcHelou
New Member

let's say i have a file that I would like to input it to splunk.
but I want to have a better parser, a smarter one. how can I change the way splunk handles the incoming streams, not just taking each line by its own but applying my own code on how to arrange streams of data.

0 Karma

woodcock
Esteemed Legend

File a P1 Enhancement Request (there already is one for this).

0 Karma

MarcHelou
New Member

can you be more specific please?
Do you mean the support programs?
in other ways what I am trying to look for is a way to change the parser in splunk, so splitting income data happens in a different way than what splunk offers

0 Karma

davebrooking
Contributor

Can you provide some examples of how the data may appear in the original file, and how that data should then be indexed by Splunk?

0 Karma

micahkemp
Champion

Have you looked into Modular Inputs?

0 Karma

MarcHelou
New Member

Yes but I want to try and change how splunk arranges tuples from incoming streams and not only post each line as an event, for anonymity purposes. I want to specify how it cuts the incoming data into event and how to index them depending on several factors

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...