Getting Data In

Sending syslog without any header

hswoo2000
Explorer

Hi All

When a firwall logs go to the Splunk and the Splunk redirects to our log collector, additional timestamp and syslog headers to the packet. It makes the logs indecipherable once they reach our log collector.

Any solution passing logs without any log format changes?

Thanks,

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You can use the setting in Splunk inputs.conf no_appending_timestamp. See the README file or docs for inputs.conf.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...