Getting Data In

How to use the universal forwarder to parse log files with a key value pair format and forward to splunk cloud

cameronharris6
New Member

Hello,

I'm trying to parse log entries that look like so

EventTime=2018-12-07 10:06:31,Hostname=WIN-UE7JIIAK3IG.nxlog.co,Keywords=36028797018963968,EventType=INFO,SeverityValue=2,Severity=INFO,EventID=1,SourceName='My Script',TaskValue=1,RecordNumber=3169,ExecutionProcessID=0,ExecutionThreadID=0,Channel=Application,Message='This is a test message 1.',Opcode=Info,EventData='<Data>This is a test message 1.</Data>',EventReceivedTime=2018-11-26 14:16:31,SourceModuleName=filein,SourceModuleType=mymodulelog,
EventTime=2018-12-07 10:16:33,Hostname=WIN-UE7JIIAK3IG.nxlog.co,Keywords=36028797018963968,EventType=INFO,SeverityValue=2,Severity=INFO,EventID=1,SourceName='My Script',TaskValue=1,RecordNumber=3170,ExecutionProcessID=0,ExecutionThreadID=0,Channel=Application,Message='This is a test message 2.',Opcode=Info,EventData='<Data>This is a test message 2.</Data>',EventReceivedTime=2018-11-26 14:16:33,SourceModuleName=filein,SourceModuleType=mymodulelog,

I'd like to forward these to my indexer on the Splunk cloud, and be searchable via field names. Something that is not clear to me is how I configure my inputs.conf and props.conf to handle such data.

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Universal forwarders do not parse data. That's done by indexers and heavy forwarders (that is not to imply you should replace a UF with a HF).

Inputs.conf goes on the UF. Props.conf goes on the indexer.

See https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Universal forwarders do not parse data. That's done by indexers and heavy forwarders (that is not to imply you should replace a UF with a HF).

Inputs.conf goes on the UF. Props.conf goes on the indexer.

See https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

&#x1f342; Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...