Splunk Search

Does Hunk support Avro as a log format?

jwalzerpitt
Influencer

Does Hunk support Avro as a log format?

We are reviewing the ETL process for the various ways we can write data to our Hadoop cluster, but want to make sure that we pick a log format that is supported by Hunk.

Thx

Tags (4)
0 Karma
1 Solution

jwalzerpitt
Influencer

Thx for the link - is there anything that needs to be done in transforms/props to support the schema options, or is it basically point Hunk at the data and have at it?

0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

For Avro just point to the data and if the file extension is .avro you are set.

However, If the file extension is different you will need to modify this flag in the provider or VIX
vix.splunk.search.recordreader.avro.regex = .avro$

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...