Splunk Search

Does Hunk support Avro as a log format?

jwalzerpitt
Influencer

Does Hunk support Avro as a log format?

We are reviewing the ETL process for the various ways we can write data to our Hadoop cluster, but want to make sure that we pick a log format that is supported by Hunk.

Thx

Tags (4)
0 Karma
1 Solution

jwalzerpitt
Influencer

Thx for the link - is there anything that needs to be done in transforms/props to support the schema options, or is it basically point Hunk at the data and have at it?

0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

For Avro just point to the data and if the file extension is .avro you are set.

However, If the file extension is different you will need to modify this flag in the provider or VIX
vix.splunk.search.recordreader.avro.regex = .avro$

Get Updates on the Splunk Community!

Community Feedback

We Want to Hear from You! Share Your Feedback on the Splunk Community   The Splunk Community is built for you ...

Manual Instrumentation with Splunk Observability Cloud: Implementing the ...

In our observability journey so far, we've built comprehensive instrumentation for our Worms in Space ...

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...