What is the optimal format our application can generate for splunk to pick it up by default? Development can make the format whatever it needs to be, what is best?
Hi brent_weaver,
if your development is really that nice, go for key=value
pairs and Splunk will pick it up.
cheers, MuS
PS: JSON, csv or XML will also work 😉
Hi brent_weaver,
if your development is really that nice, go for key=value
pairs and Splunk will pick it up.
cheers, MuS
PS: JSON, csv or XML will also work 😉
There's a page on logging best practices here that might contain further relevant ideas.