Getting Data In

Is it possible to use two stanza specs in props.conf?

h3llocomputer
Explorer

I have a syslog server that collects all of my network device logs (routers, switches, etc) and I have a Universal Forward set up on this server to send all of these logs to Splunk Cloud. I have a new group of devices sending logs to this syslog server and I need to edit the timezone for these new devices (I cannot edit the timestamp at the source). I know that I will need to change my forward server on the UF and change it to my Heavy Forwarder since as far as I know, I can't do any timestamp parsing on the UF.

Would I be able to use multiple specs to in props.conf to enable me to single out these specific devices AND the specific sourcetype (since I'm using a wildcard in the host spec, I want to be sure I am only getting the "syslog:network" logs)? Example:

[host::CISCO_*] AND [syslog:network]
TZ = America/Chicago

Is this possible, or am I doomed to creating a stanza for each host device?

woodcock
Esteemed Legend

It is a little known fact that as of v6.6 Indexers will honor the TZ= setting as it exists on the UF in preference to anything that exists on the Indexer. So just use a sourcetype-based setting on the syslog-ng UF.

0 Karma

h3llocomputer
Explorer

Interesting. Would this setting live in props.conf on the UF or in some other file?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...