Getting Data In

How do you parse a log with one JSON object per line which is being sent by a forwarder?

wtanaka
Explorer

this solution worked for me for log files that are on the same machine as the splunk server. But when I started forwarding logs from a universal forwarder on a separate machine to the same server, the same props.conf and transforms.conf setup no longer parses out the timestamp. When do props.conf and transforms.conf get applied? Do the raw log lines get forwarded to the server, where they are parsed with props/transforms? Or do I need to apply props/transforms on the universal forwarder machine?

0 Karma

rroberts
Splunk Employee
Splunk Employee

Check out this document if you haven't already.
Where do I configure my Splunk Settings?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...