Getting Data In

use transforms.conf or props.conf to convert multi line event to single event on forwarder level to send external to Splunk

New Member

I would like to convert an event similar to the one below to be a single event when sending it out to an external Syslog server

time: 20180717112345
dn: uid=123,ou=employees,ou=ddd,ou=ddd,o=ddd,dc=ddd,dc=ddd
changetype: modify
replace: userPassword

userPassword: #####

replace: modifiersName
modifiersName: uid=ddd,ou=ddd,ou=ddd,ou=ddd,o=ddd,dc=ddd,


replace: modifyTimestamp

modifyTimestamp: 20180717112345Z

replace: accountUnlockTime

replace: passwordRetryCount

passwordRetryCount: 0

replace: retryCountResetTime

replace: pwdFailureTime

replace: pwdAccountLockedTime

0 Karma


a uf will ignore props and transforms, you will need a heavy forwarder on your syslog server.

0 Karma

New Member

I have a heavy forwarder on the rsyslog server but the rsyslog is taking each line as a separate event

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!