Getting Data In

forwarder logs different type from the indexer.

lifekis
Explorer

I want to use forwarder to forward mail logs to indexer.
However, the log forwarded from the forwarder is displayed separately from the indexer.
how can i solve it.

start character: MAIL_LOG
end character: END_MAIL

[[[forwarder log file]]]
ex1) The forwarder log file looks like this:
MAIL_LOG
date:2019-00-00 00:00:00
subject: abcdefg
from: abc@abc.com
to:abcd@abcd.com
size:12345
content:afafa
...
END_MAIL

[[[indexer]]]
The log is divided.

ex1) only mail start characters logs.
MAIL_LOG

ex2) only part of the message logs.
content:afafa

ex3) Do not include the mail start character logs. MAIL_LOG
date:2019-00-00 00:00:00
subject: abcdefg
from: abc@abc.com
to:abcd@abcd.com
size:12345

0 Karma

gaurav_maniar
Builder

provide the screenshot of the log file and the same data in Splunk.
I think, the issue is because of sourcetype configuration for multiline event.

richgalloway
SplunkTrust
SplunkTrust

Please explain more about what you mean by "the log forwarded from the forwarder is displayed separately from the indexer". Use actual example events, but hide private information.

---
If this reply helps you, Karma would be appreciated.

lifekis
Explorer

The forwarder can check the log file in full format. However, the log is truncated on the indexer.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Your props.conf settings probably need to be adjusted. Please provide some sample events and we'll try to help you get the settings right.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...