Hi,
I want to sc4s to receive syslog and I want sc4s to write raw message into a directory. However, it doesn't write the raw message. There are only export messages (json) write into archive folder. What is my mistake? And which the directory was written to.
Thank you
########### env_file ############
SPLUNK_HEC_URL=https://xx.xx.xx.xx:8088
SPLUNK_HEC_TOKEN=xxxxxxxxxxxxxxxxxxxxx
SC4S_DEST_SPLUNK_HEC_TLS_VERIFY=no
#SC4S_USE_REVERSE_DNS=yes
SC4S_LISTEN_FORTINET_UDP_PORT=514
SC4S_GLOBAL_ARCHIVE_MODE=compliance
SC4S_ARCHIVE_GLOBAL=yes
SC4S_SOURCE_STORE_RAWMSG=yes
SC4S_DEST_GLOBAL_ALTERNATES=d_hec_debug,d_archive,d_rawmsg
I, too, am having this problem. We are working from this document:
https://splunk.github.io/splunk-connect-for-syslog/2.30.1/troubleshooting/troubleshoot_resources/