Getting Data In

Tar.gz

Stun
New Member

Hello,


I push in splunk a tar.gz file named file.tar.gz.
In this tar.gz file I have several files:

file.tar.gz
   |
   | - filea
   | - fileb
   | - filec

When splunk consume the tar.gz I loose the file name (I can see only the file.tar.gz file as source field).
the content of filea fileb filec are in the index but not the file name.

I would like to manage the source field with the file name in tar.gz, as following


source:filea instead of file.tar.gz

source:fileb instead of file.tar.gz

source:filec instead of file.tar.gz

Could you please help me please ?

Many thanks.

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

IMO, Splunk is showing the correct source.  The data it ingested came from file.tar.gz, not filea, fileb, or filec.

I'm not aware of a setting that will change the behavior.  Consider extracting the tarball to a directory Splunk is monitoring.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...