Getting Data In

SC4S, how do I write raw message into a directory?

karn
Path Finder

Hi,

I want to sc4s to receive syslog and I want sc4s to write raw message into a directory.  However, it doesn't write the raw message. There are only export messages (json) write into archive folder. What is my mistake?  And which the directory was written to.

Thank you

########### env_file ############

SPLUNK_HEC_URL=https://xx.xx.xx.xx:8088
SPLUNK_HEC_TOKEN=xxxxxxxxxxxxxxxxxxxxx
SC4S_DEST_SPLUNK_HEC_TLS_VERIFY=no
#SC4S_USE_REVERSE_DNS=yes

SC4S_LISTEN_FORTINET_UDP_PORT=514

SC4S_GLOBAL_ARCHIVE_MODE=compliance
SC4S_ARCHIVE_GLOBAL=yes


SC4S_SOURCE_STORE_RAWMSG=yes
SC4S_DEST_GLOBAL_ALTERNATES=d_hec_debug,d_archive,d_rawmsg

Labels (3)
Tags (1)

woodcock
Esteemed Legend

I, too, am having this problem.  We are working from this document:

https://splunk.github.io/splunk-connect-for-syslog/2.30.1/troubleshooting/troubleshoot_resources/

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Splunk Observability Metrics Cost Optimization

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...