Reporting

CSV syslogs

phoenixt
New Member

I would like to know if and where my syslog files are kept. Are they in CSV format? I would like to be able to use them with other applications also if need be.

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

If you'd like to use that data with other applications you can forward data onto other systems or you can use our API to extract the data. See links below. You could perform searches and export data to CSV if you want to do it manually for some reason as well.

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Forwarddatatothird-partysystemsd

http://dev.splunk.com/view/sdks/SP-CAAADP7

0 Karma

MHibbin
Influencer

Syslog file for... what? ... What Application/Appliance/Server/System/etc?

Usually when talking about syslog, people normally mean logs that transmitted over UDP 514 (by default), so if you are transmitting these logs already, then you need to set Splunk up to monitor that port (via the manager).

If you mean system logs, the location can vary, for example Linux store logs in the /var/log/ directory, applications may vary.

Chances they will be in clear text (human readable) format as the purpose of logs is to be read by a techie for troubleshooting (etc.)


---OR---


Another way of reading this is that you have Splunk'd your syslog files and are looking for them in Splunk... perhaps try "sourcetype=syslog" in the flashtimeline. You can output data in CSV format once you have found events yes.

Can you clarify what you mean/trying to do please? - it may be me being a bit "thick" (if it is I apologise).

Cheers,

MHibbin

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...