Getting Data In

Sending syslog without any header

hswoo2000
Explorer

Hi All

When a firwall logs go to the Splunk and the Splunk redirects to our log collector, additional timestamp and syslog headers to the packet. It makes the logs indecipherable once they reach our log collector.

Any solution passing logs without any log format changes?

Thanks,

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You can use the setting in Splunk inputs.conf no_appending_timestamp. See the README file or docs for inputs.conf.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...