Splunk Cloud Platform

Is there any case where Splunk can perform parsing without an add-on help?

SplunkExplorer
Communicator

Hi Splunkers,

I have a doubt about the Splunk parsing capacity.

Until now, every time I needed to parse data, I used add-on, both custome wrote by me and downloaded from Splunk base. If I remeber well, but correct me if I'm wrong, an add-on is not required (or may be not required) if we have a well structured data format, like JSON or XML .

My question is: if the above assumption is right, are there any other case where Splunk can perform parsing without an add-on help? And if yes, what are they?

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Just because the data is well-formed doesn't mean Splunk knows what to do with it.  Add-ons tell Splunk how to process data.  This saves Splunk from guessing incorrectly and speeds onboarding.

The one format Splunk will parse out-of-the-box is key=value.  Even then, an add-on is recommended.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Just because the data is well-formed doesn't mean Splunk knows what to do with it.  Add-ons tell Splunk how to process data.  This saves Splunk from guessing incorrectly and speeds onboarding.

The one format Splunk will parse out-of-the-box is key=value.  Even then, an add-on is recommended.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...