Getting Data In

How can I omit the timestamp and host that splunk automatically add to my logs

dadi
Path Finder

hi guys,
I've added my first logs in splunk today. I notice that in the beginning of each row splunk has added a prefix of timestamp and host. For example this is a single log line(refer to the bold text):

Jun 29 16:16:44 127.0.0.1 2011-06-29 16:16:44.067 [main ] INFO com.cloudon.VabConnector - About to activate VabConnector with parameters node id [1], ZK_connect_str[127.0.0.1:2181], VabConnectionServerPort[8000], ownIp[10.0.0.8]

I've configured my channel in the web interface in - Home » Add Data » UDP » Add New

I've defined it as syslog source type and I'm sending the logs from my application. I've used wireshark to verify that the message I send is without the prefix.

Do you know why splunk add this prefix?

More importantly, I can I remove it from the logs?

Thanks,
Eldad.

Tags (1)
0 Karma
1 Solution

dadi
Path Finder

I found the answer in here

View solution in original post

0 Karma

dadi
Path Finder

I found the answer in here

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...