Splunk Search

Does Hunk support Avro as a log format?

jwalzerpitt
Influencer

Does Hunk support Avro as a log format?

We are reviewing the ETL process for the various ways we can write data to our Hadoop cluster, but want to make sure that we pick a log format that is supported by Hunk.

Thx

Tags (4)
0 Karma
1 Solution

jwalzerpitt
Influencer

Thx for the link - is there anything that needs to be done in transforms/props to support the schema options, or is it basically point Hunk at the data and have at it?

0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

For Avro just point to the data and if the file extension is .avro you are set.

However, If the file extension is different you will need to modify this flag in the provider or VIX
vix.splunk.search.recordreader.avro.regex = .avro$

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...