Getting Data In

How do I correctly index github enterprise logs?

dpwtheitguy
Loves-to-Learn Lots

All, 

I am looking GitHub Enterprise logs as captured by my Syslog-ng server on prem. The logs being sent are JSON ...mostly, but we have some values in the JSON key-value-pairs that are breaking characters. The app is not escaping these characters. 

SEDCMDing all the these events at the indexer were just overwhelming and don't think this is the correct approach. 

I am looking the Splunk Add-on for GitHub and I am seeing it wants Splunk for Syslog Connect container deployed. Before I go and deploy that and learn how it works and what not, how can I check that Splunk has already solved this problem? Just don't want to build that sort of lab out and found out there isn't already some sort of work around in this tool for escaping json chars. 

 

thanks
-Daniel 

Labels (2)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...