Getting Data In

SC4S, how do I write raw message into a directory?

karn
Path Finder

Hi,

I want to sc4s to receive syslog and I want sc4s to write raw message into a directory.  However, it doesn't write the raw message. There are only export messages (json) write into archive folder. What is my mistake?  And which the directory was written to.

Thank you

########### env_file ############

SPLUNK_HEC_URL=https://xx.xx.xx.xx:8088
SPLUNK_HEC_TOKEN=xxxxxxxxxxxxxxxxxxxxx
SC4S_DEST_SPLUNK_HEC_TLS_VERIFY=no
#SC4S_USE_REVERSE_DNS=yes

SC4S_LISTEN_FORTINET_UDP_PORT=514

SC4S_GLOBAL_ARCHIVE_MODE=compliance
SC4S_ARCHIVE_GLOBAL=yes


SC4S_SOURCE_STORE_RAWMSG=yes
SC4S_DEST_GLOBAL_ALTERNATES=d_hec_debug,d_archive,d_rawmsg

Labels (3)
Tags (1)

woodcock
Esteemed Legend

I, too, am having this problem.  We are working from this document:

https://splunk.github.io/splunk-connect-for-syslog/2.30.1/troubleshooting/troubleshoot_resources/

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...