Splunk Search

Does Hunk support Avro as a log format?

Motivator

Does Hunk support Avro as a log format?

We are reviewing the ETL process for the various ways we can write data to our Hadoop cluster, but want to make sure that we pick a log format that is supported by Hunk.

Thx

Tags (4)
0 Karma
1 Solution

Motivator

Thx for the link - is there anything that needs to be done in transforms/props to support the schema options, or is it basically point Hunk at the data and have at it?

0 Karma

Splunk Employee
Splunk Employee

For Avro just point to the data and if the file extension is .avro you are set.

However, If the file extension is different you will need to modify this flag in the provider or VIX
vix.splunk.search.recordreader.avro.regex = .avro$