Getting Data In

Props and Transforms doubt

splunklearner
Communicator

I am pretty new to Splunk and my project is also new. Can someone please explain the configurations given in our cluster manager. We have a syslog server which receives logs from F5 WAF devices and UF in syslog server forwards the data to our cluster manager.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Based on these conf files it seems to do next.

  1. Take timestamp from beginning of event and put it into _time
  2. Ensure that lines are not longer than 10000 characters 
  3. syslog-host transformation is missing, so I cannot tell what it do!
  4. extract hostname from event and save it into metadata to use on next step
  5. define used index based on hostname (fqdn) on event. Fqdn vs index is defined on that csv lookup file
  6. Change \r\n newline to just \n 
  7. Don't generate punctuation for event

More detailed information from those links which @PaulPanther add in his post.

r. Ismo

0 Karma

PaulPanther
Motivator
0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with William Searle

The Splunk Guy: A Developer’s Path from Web to Cloud William is a Splunk Professional Services Consultant with ...

Major Splunk Upgrade – Prepare your Environment for Splunk 10 Now!

Attention App Developers: Test Your Apps with the Splunk 10.0 Beta and Ensure Compatibility Before the ...

Stay Connected: Your Guide to June Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...