Getting Data In

Sourcetypes on UDP syslog data

timmy13
Communicator

When receiving syslog data via UDP:514, is there a way to specify the sourcetype based on the IP address of the device sending the data?

0 Karma

ryanoconnor
Builder

It looks like could possibly work for what you need. You can also look into installing syslog-ng, kiwi syslog, or rsyslog on your server. This would allow for more advanced filtering of data and you could send data to different directories as it was being collected.

From there you could have different monitoring stanzas to look at different directories of data and assign sourcetypes that way. That's probably the cleanest way to do it and the most recommended so that you won't have any data loss in the event that Splunk needs to be restarted or shuts down unexpectedly.

0 Karma

ddrillic
Ultra Champion
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...