Getting Data In

SC4S, how do I write raw message into a directory?

karn
Path Finder

Hi,

I want to sc4s to receive syslog and I want sc4s to write raw message into a directory.  However, it doesn't write the raw message. There are only export messages (json) write into archive folder. What is my mistake?  And which the directory was written to.

Thank you

########### env_file ############

SPLUNK_HEC_URL=https://xx.xx.xx.xx:8088
SPLUNK_HEC_TOKEN=xxxxxxxxxxxxxxxxxxxxx
SC4S_DEST_SPLUNK_HEC_TLS_VERIFY=no
#SC4S_USE_REVERSE_DNS=yes

SC4S_LISTEN_FORTINET_UDP_PORT=514

SC4S_GLOBAL_ARCHIVE_MODE=compliance
SC4S_ARCHIVE_GLOBAL=yes


SC4S_SOURCE_STORE_RAWMSG=yes
SC4S_DEST_GLOBAL_ALTERNATES=d_hec_debug,d_archive,d_rawmsg

Labels (3)
Tags (1)

woodcock
Esteemed Legend

I, too, am having this problem.  We are working from this document:

https://splunk.github.io/splunk-connect-for-syslog/2.30.1/troubleshooting/troubleshoot_resources/

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...