Getting Data In

no_appending_timestamp and syslog-ng clarification

mikefg
Communicator

Just need to clarify - if I'm using syslog-ng to receive udp syslog I do not need the no_appending_timestamp = true in inputs.conf, correct? The no_appending_timestamp = true is used when receiving udp and not using a log collector like syslog-ng.

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You do not need to set no_appending_timestamp=true.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

You do not need to set no_appending_timestamp=true.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...