Getting Data In

use transforms.conf or props.conf to convert multi line event to single event on forwarder level to send external to Splunk

ssyed2009
New Member

I would like to convert an event similar to the one below to be a single event when sending it out to an external Syslog server


time: 20180717112345
dn: uid=123,ou=employees,ou=ddd,ou=ddd,o=ddd,dc=ddd,dc=ddd
changetype: modify
replace: userPassword

userPassword: #####

replace: modifiersName
modifiersName: uid=ddd,ou=ddd,ou=ddd,ou=ddd,o=ddd,dc=ddd,

dc=ddd

replace: modifyTimestamp

modifyTimestamp: 20180717112345Z

replace: accountUnlockTime

replace: passwordRetryCount

passwordRetryCount: 0

replace: retryCountResetTime

replace: pwdFailureTime

replace: pwdAccountLockedTime


0 Karma

CarsonZa
Contributor

a uf will ignore props and transforms, you will need a heavy forwarder on your syslog server.

0 Karma

ssyed2009
New Member

I have a heavy forwarder on the rsyslog server but the rsyslog is taking each line as a separate event

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...

Auto-Injector for Everything Else: Making OpenTelemetry Truly Universal

You might have seen Splunk’s recent announcement about donating the OpenTelemetry Injector to the ...