Getting Data In

Sourcetype questions

templier
Communicator

Hello, colleagues!

Ask for help.
I have a log species:

Nov  7 17:31:50 domain.domain {"user":"email@domain","mimetype":"image\/gif","filename":"Logo_Facebook.gif","disposition":"attachment","size":5998,"download":false}

it is necessary to handle in splunk.

Possible to handle this file at the entrance to the forwarder and already transmitted in a suitable form in splunk?

Thank you!

0 Karma
1 Solution

templier
Communicator

Hello, colleagues!

Found simply irreplaceable application and creat a sourcetype.
Called - Universal Field Extractor

View solution in original post

0 Karma

templier
Communicator

Hello, colleagues!

Found simply irreplaceable application and creat a sourcetype.
Called - Universal Field Extractor

0 Karma

templier
Communicator

How i undestend i must do it on splunk indexer (server) I'm right?

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...