Getting Data In

use transforms.conf or props.conf to convert multi line event to single event on forwarder level to send external to Splunk

ssyed2009
New Member

I would like to convert an event similar to the one below to be a single event when sending it out to an external Syslog server


time: 20180717112345
dn: uid=123,ou=employees,ou=ddd,ou=ddd,o=ddd,dc=ddd,dc=ddd
changetype: modify
replace: userPassword

userPassword: #####

replace: modifiersName
modifiersName: uid=ddd,ou=ddd,ou=ddd,ou=ddd,o=ddd,dc=ddd,

dc=ddd

replace: modifyTimestamp

modifyTimestamp: 20180717112345Z

replace: accountUnlockTime

replace: passwordRetryCount

passwordRetryCount: 0

replace: retryCountResetTime

replace: pwdFailureTime

replace: pwdAccountLockedTime


0 Karma

CarsonZa
Contributor

a uf will ignore props and transforms, you will need a heavy forwarder on your syslog server.

0 Karma

ssyed2009
New Member

I have a heavy forwarder on the rsyslog server but the rsyslog is taking each line as a separate event

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>