Getting Data In

Is it possible to use two stanza specs in props.conf?

h3llocomputer
Explorer

I have a syslog server that collects all of my network device logs (routers, switches, etc) and I have a Universal Forward set up on this server to send all of these logs to Splunk Cloud. I have a new group of devices sending logs to this syslog server and I need to edit the timezone for these new devices (I cannot edit the timestamp at the source). I know that I will need to change my forward server on the UF and change it to my Heavy Forwarder since as far as I know, I can't do any timestamp parsing on the UF.

Would I be able to use multiple specs to in props.conf to enable me to single out these specific devices AND the specific sourcetype (since I'm using a wildcard in the host spec, I want to be sure I am only getting the "syslog:network" logs)? Example:

[host::CISCO_*] AND [syslog:network]
TZ = America/Chicago

Is this possible, or am I doomed to creating a stanza for each host device?

woodcock
Esteemed Legend

It is a little known fact that as of v6.6 Indexers will honor the TZ= setting as it exists on the UF in preference to anything that exists on the Indexer. So just use a sourcetype-based setting on the syslog-ng UF.

0 Karma

h3llocomputer
Explorer

Interesting. Would this setting live in props.conf on the UF or in some other file?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...