Hi there,
Logs sent to SC4S include date, time and host in the event, however when they are sent to Indexer, the date, time and host are missing. How can I get them back so the logs will look exactly the same?
I would like date, time and host included in the event.
I appreciate any hints.
thanks and regards, pawelF
You need to look at how the input is processed and the definition of inputs.conf/props.conf for that linux sourcetype.
As you can see in that event example, the time in the log message is 15:04:57, but the time in the Splunk event is 15:03:57, i.e. a minute earlier - so that date is not the one being used when Splunk is ingested.
I am not familiar with SC4S, but has someone written a parser for that data - if so, it may be that the issue is at the SC4S parsing end.