Splunk Search

Does Hunk support Avro as a log format?

jwalzerpitt
Influencer

Does Hunk support Avro as a log format?

We are reviewing the ETL process for the various ways we can write data to our Hadoop cluster, but want to make sure that we pick a log format that is supported by Hunk.

Thx

Tags (4)
0 Karma
1 Solution

jwalzerpitt
Influencer

Thx for the link - is there anything that needs to be done in transforms/props to support the schema options, or is it basically point Hunk at the data and have at it?

0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

For Avro just point to the data and if the file extension is .avro you are set.

However, If the file extension is different you will need to modify this flag in the provider or VIX
vix.splunk.search.recordreader.avro.regex = .avro$

Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...