Getting Data In

no_appending_timestamp and syslog-ng clarification

Path Finder

Just need to clarify - if I'm using syslog-ng to receive udp syslog I do not need the no_appending_timestamp = true in inputs.conf, correct? The no_appending_timestamp = true is used when receiving udp and not using a log collector like syslog-ng.

Tags (2)
0 Karma
1 Solution

SplunkTrust
SplunkTrust

You do not need to set no_appending_timestamp=true.

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

You do not need to set no_appending_timestamp=true.

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!