Splunk Enterprise

Does splunk support RFC 5424 format?

erickyi
Path Finder

Hi All,

The older version does not support RFC 5424. And in the latest doco, it mentioned that forwarding to 3rd party supports the old style syslog (RFC 3164).

Please confirm. If not, please tell us the work around on how we can support the newer syslog format. If we need to add an add-on, we will do so.

Kindest Regards
Ricky

0 Karma
1 Solution

erickyi
Path Finder

Found a solution. There is an addon we can use
https://splunkbase.splunk.com/app/978/

Hope this is useful to others who are facing the same requirement (to support RFC 5424)

View solution in original post

erickyi
Path Finder

Found a solution. There is an addon we can use
https://splunkbase.splunk.com/app/978/

Hope this is useful to others who are facing the same requirement (to support RFC 5424)

Get Updates on the Splunk Community!

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...