Getting Data In

we are not able to ingest data from *.act and *.authlog files but we can ingest the .csv and .log file format.

Hemant93
Loves-to-Learn Lots

Help me out to ingest .act and .authlog file format in splunk.

Labels (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You need to define the format or at least how to find and extract the fields you want from the events in the logs. Just giving the file extension does not define the format. Assumptions can sometimes be made about .csv file formats, for example, but lesser-known formats, not so much.

Get Updates on the Splunk Community!

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

Unlock Instant Security Insights from Amazon S3 with Splunk Cloud — Try Federated ...

Availability: Must be on Splunk Cloud Platform version 10.1.2507.x to view the free trial banner. If you are ...