Getting Data In

How do I correctly index github enterprise logs?

dpwtheitguy
Loves-to-Learn Lots

All, 

I am looking GitHub Enterprise logs as captured by my Syslog-ng server on prem. The logs being sent are JSON ...mostly, but we have some values in the JSON key-value-pairs that are breaking characters. The app is not escaping these characters. 

SEDCMDing all the these events at the indexer were just overwhelming and don't think this is the correct approach. 

I am looking the Splunk Add-on for GitHub and I am seeing it wants Splunk for Syslog Connect container deployed. Before I go and deploy that and learn how it works and what not, how can I check that Splunk has already solved this problem? Just don't want to build that sort of lab out and found out there isn't already some sort of work around in this tool for escaping json chars. 

 

thanks
-Daniel 

Labels (2)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...