Hi,
When I set no_priority_stripping = true in input.conf in Splunk server, my syslog data send to Splunk work but a very long delay of time.
When I remove no_priority_stripping = true from input.conf. My unit sends syslog to Splunk in real-time.
I do need to set no_priority_stripping = true, in order for me to use syslog_priority.csv lookup table.
I need help to resolve this issue. Can you please point me in the right direction?
Thanks,
Matoula Senethavong