Hello, colleagues!
Ask for help.
I have a log species:
Nov 7 17:31:50 domain.domain {"user":"email@domain","mimetype":"image\/gif","filename":"Logo_Facebook.gif","disposition":"attachment","size":5998,"download":false}
it is necessary to handle in splunk.
Possible to handle this file at the entrance to the forwarder and already transmitted in a suitable form in splunk?
Thank you!
Hello, colleagues!
Found simply irreplaceable application and creat a sourcetype.
Called - Universal Field Extractor
Hello, colleagues!
Found simply irreplaceable application and creat a sourcetype.
Called - Universal Field Extractor
How i undestend i must do it on splunk indexer (server) I'm right?