Getting Data In

Props and Transforms doubt

splunklearner
Communicator

I am pretty new to Splunk and my project is also new. Can someone please explain the configurations given in our cluster manager. We have a syslog server which receives logs from F5 WAF devices and UF in syslog server forwards the data to our cluster manager.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Based on these conf files it seems to do next.

  1. Take timestamp from beginning of event and put it into _time
  2. Ensure that lines are not longer than 10000 characters 
  3. syslog-host transformation is missing, so I cannot tell what it do!
  4. extract hostname from event and save it into metadata to use on next step
  5. define used index based on hostname (fqdn) on event. Fqdn vs index is defined on that csv lookup file
  6. Change \r\n newline to just \n 
  7. Don't generate punctuation for event

More detailed information from those links which @PaulPanther add in his post.

r. Ismo

0 Karma

PaulPanther
Motivator
0 Karma
Get Updates on the Splunk Community!

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Announcing the General Availability of Splunk Enterprise Security 8.1!

We are pleased to announce the general availability of Splunk Enterprise Security 8.1. Splunk becomes the only ...

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...