Getting Data In

Why props.conf not getting picked up while ingesting data through HEC, /event endpoint?

neha898
New Member

Why props.conf not getting picked up while ingesting data through HEC, /event endpoint?

0 Karma
1 Solution

starcher
Influencer

Only raw gets sent through the parsing queue. Using event presumes you are properly formatting your event in JSON and the JSON extraction handles everything. This is expected behavior.

View solution in original post

starcher
Influencer

Only raw gets sent through the parsing queue. Using event presumes you are properly formatting your event in JSON and the JSON extraction handles everything. This is expected behavior.

neha898
New Member

I guess this is the confirmation I was looking for, so docker container logs should be ingested into SPlunk via the raw endpoint if we want to parse them at Splunk end.

0 Karma

starcher
Influencer

keep in mind search time extractions are different than say even breaking and time stamping at the HF where HEC runs. so for the HF yes that is as I said and you'd need to be on raw.

0 Karma

neha898
New Member

Thanks a lot @starcher

0 Karma

xavierashe
Contributor

Let me ask a clairifying question. Are you collecting event through a HEC input on a heavy fowarder, and it doesn't seem to apply your props config? Can you post a sample event and your props.conf?

0 Karma

neha898
New Member

Yes, I am trying to collect events via HEC. Splunk is smartly formatting the timestamp, issue is that each exception form docker is getting posted as a separate event on a new line preceded by a containerid. My main doubt is that does props.conf on HF get picked up for HEC collector/event endpoint? I read on my other answers on this forum that /event endpoint doesn't pickup props and transforms processing.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...