Getting Data In

Props and Transforms doubt

splunklearner
Communicator

I am pretty new to Splunk and my project is also new. Can someone please explain the configurations given in our cluster manager. We have a syslog server which receives logs from F5 WAF devices and UF in syslog server forwards the data to our cluster manager.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Based on these conf files it seems to do next.

  1. Take timestamp from beginning of event and put it into _time
  2. Ensure that lines are not longer than 10000 characters 
  3. syslog-host transformation is missing, so I cannot tell what it do!
  4. extract hostname from event and save it into metadata to use on next step
  5. define used index based on hostname (fqdn) on event. Fqdn vs index is defined on that csv lookup file
  6. Change \r\n newline to just \n 
  7. Don't generate punctuation for event

More detailed information from those links which @PaulPanther add in his post.

r. Ismo

0 Karma

PaulPanther
Motivator
0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...