Getting Data In
Highlighted

Indexing ZIP files

Communicator

Can Splunk index gzip/zip files (flat-file format)?

Tags (4)
Highlighted

Re: Indexing ZIP files

Legend
Highlighted

Re: Indexing ZIP files

Communicator

OK, good. Are there config changes that need to occur?

0 Karma
Highlighted

Re: Indexing ZIP files

Communicator

props.conf, transforms.conf

0 Karma
Highlighted

Re: Indexing ZIP files

Legend

Nope! It indexes it right out of the box.

0 Karma
Highlighted

Re: Indexing ZIP files

SplunkTrust
SplunkTrust

Pedantic reminder that "zip" != "gzip". One of these (.zip) is the venerable PKZIP format that allows multiple files within an archive. The other (.gz) is the gzip single-file compression format.

Highlighted

Re: Indexing ZIP files

Path Finder
0 Karma