Getting Data In

Props and Transforms doubt

splunklearner
Communicator

I am pretty new to Splunk and my project is also new. Can someone please explain the configurations given in our cluster manager. We have a syslog server which receives logs from F5 WAF devices and UF in syslog server forwards the data to our cluster manager.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Based on these conf files it seems to do next.

  1. Take timestamp from beginning of event and put it into _time
  2. Ensure that lines are not longer than 10000 characters 
  3. syslog-host transformation is missing, so I cannot tell what it do!
  4. extract hostname from event and save it into metadata to use on next step
  5. define used index based on hostname (fqdn) on event. Fqdn vs index is defined on that csv lookup file
  6. Change \r\n newline to just \n 
  7. Don't generate punctuation for event

More detailed information from those links which @PaulPanther add in his post.

r. Ismo

0 Karma

PaulPanther
Motivator
0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...