Getting Data In

splunk event miss data

bjlotsplunk
New Member

Hi
splunk event receive syslog ,but it didn'nt appear msg type.
for example
kiwisyslog or 3cdemonalt text

splunk only display "Message"
thank you

Tags (1)
0 Karma

nickhills
Ultra Champion

That is expected behaviour.

Syslog will only send the "Message" - what you are showing in your screenshot is how your syslog server renders the data for you.

Side Note: I would be a bit alarmed that your syslog server appears to receive the message 14 -17 seconds before the client has sent it!
I'm not familiar with the tool pictured, but it might suggest you have a time sync issue to deal with.

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...