Splunk Enterprise

Does splunk support RFC 5424 format?

erickyi
Path Finder

Hi All,

The older version does not support RFC 5424. And in the latest doco, it mentioned that forwarding to 3rd party supports the old style syslog (RFC 3164).

Please confirm. If not, please tell us the work around on how we can support the newer syslog format. If we need to add an add-on, we will do so.

Kindest Regards
Ricky

0 Karma
1 Solution

erickyi
Path Finder

Found a solution. There is an addon we can use
https://splunkbase.splunk.com/app/978/

Hope this is useful to others who are facing the same requirement (to support RFC 5424)

View solution in original post

erickyi
Path Finder

Found a solution. There is an addon we can use
https://splunkbase.splunk.com/app/978/

Hope this is useful to others who are facing the same requirement (to support RFC 5424)

Get Updates on the Splunk Community!

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...