Splunk Search

Field extraction - limited interesting and selected fields

ezparra05
Engager

Hi,

Are there apps to help with the extraction of sourcetype = linux_syslog. I have hosts(solaris,rhel,etc) sending logs over udp on discrete ports and the limited fields and selected fields are really limited. Yes, I know it is not recommended to send syslog directly to splunk but this is will have to do until we can purchase hardware and setup a syslog server. Also, I am not able to install UF on these hosts either.

Any help is much appreciated!

Labels (1)
0 Karma

ezparra05
Engager

The  "Splunk Add-on for Unix and Linux" does not solve my issue and I can not install the UF on these hosts.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ezparra05,

did you tried with the "Splunk Add-On for Unix and Linux (https://splunkbase.splunk.com/app/833/)?

Anyway, see if you can use a Universal Forwarder is definitely very better than syslogs!

Ciao.

Giuseppe

0 Karma

ezparra05
Engager

Hi @gcusello ,

Yes, I already do have the "Splunk Add-on for Unix and Linux" installed.  Thank you!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ezparra05,

good for you,

if this answer solves your need, please, accept it for the other people of Community, otherwise, please tell me how can I help you.

Ciao.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...