Getting Data In

Props and Transforms doubt

splunklearner
Communicator

I am pretty new to Splunk and my project is also new. Can someone please explain the configurations given in our cluster manager. We have a syslog server which receives logs from F5 WAF devices and UF in syslog server forwards the data to our cluster manager.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Based on these conf files it seems to do next.

  1. Take timestamp from beginning of event and put it into _time
  2. Ensure that lines are not longer than 10000 characters 
  3. syslog-host transformation is missing, so I cannot tell what it do!
  4. extract hostname from event and save it into metadata to use on next step
  5. define used index based on hostname (fqdn) on event. Fqdn vs index is defined on that csv lookup file
  6. Change \r\n newline to just \n 
  7. Don't generate punctuation for event

More detailed information from those links which @PaulPanther add in his post.

r. Ismo

0 Karma

PaulPanther
Motivator
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...