Getting Data In

Why props.conf not getting picked up while ingesting data through HEC, /event endpoint?

neha898
New Member

Why props.conf not getting picked up while ingesting data through HEC, /event endpoint?

0 Karma
1 Solution

starcher
Influencer

Only raw gets sent through the parsing queue. Using event presumes you are properly formatting your event in JSON and the JSON extraction handles everything. This is expected behavior.

View solution in original post

starcher
Influencer

Only raw gets sent through the parsing queue. Using event presumes you are properly formatting your event in JSON and the JSON extraction handles everything. This is expected behavior.

neha898
New Member

I guess this is the confirmation I was looking for, so docker container logs should be ingested into SPlunk via the raw endpoint if we want to parse them at Splunk end.

0 Karma

starcher
Influencer

keep in mind search time extractions are different than say even breaking and time stamping at the HF where HEC runs. so for the HF yes that is as I said and you'd need to be on raw.

0 Karma

neha898
New Member

Thanks a lot @starcher

0 Karma

xavierashe
Contributor

Let me ask a clairifying question. Are you collecting event through a HEC input on a heavy fowarder, and it doesn't seem to apply your props config? Can you post a sample event and your props.conf?

0 Karma

neha898
New Member

Yes, I am trying to collect events via HEC. Splunk is smartly formatting the timestamp, issue is that each exception form docker is getting posted as a separate event on a new line preceded by a containerid. My main doubt is that does props.conf on HF get picked up for HEC collector/event endpoint? I read on my other answers on this forum that /event endpoint doesn't pickup props and transforms processing.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...