Getting Data In

Splunk 6.0 removing syslog priority fields

herat420
New Member

Dear sir

I have read all information on the Splunk answers. but I couldnt find any solutionn for my situation. I am new in the world of splunk and splunk is running in test lab. I can forward syslog to splunkm but splunk remove priority fields from syslog. I have add the following code in the inpust.conf file and restart the splunk, but it didnt solved my problem.

C:\Program Files\Splunk\etc\system\local\inputs.conf
[udp://514]
no_priority_stripping = true

I tried also this location:
C:\Program Files\Splunk\etc\apps\search\local\inputs.conf
[udp://514]
no_priority_stripping = true

Would anyone please tell me if am i configuring in the worng place?
If anyone can help me I would apprecaite that.
thanks in advance

Best Rrgards,

Herat

0 Karma

rkirkw
Path Finder

In 6 on Windows with the Universal Forwarder, it seems that the config files have moved to
C:\splunkuniversalforwarder\etc\apps\splunk_ta_windows\local\inputs.conf

This is the file I had to change to point the data to specific indexes.

You may try a search for other inputs.conf and see if you have one in a similar location - depending on the path you chose for $Splunk_Home

0 Karma
Get Updates on the Splunk Community!

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...