Splunk Search

What is <14> we see in Splunk logs, each log starts with <14> what does it pertain to ? can anyone answer this please?

jlsiri
Engager

<14> prefix is displayed in splunk logs, what does it mean, why is it displayed? Can anyone answer this question please?

0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

Typically syslog events sent over the network start with a <number> containing information about so called "facility" and severity of the event.  See https://datatracker.ietf.org/doc/html/rfc3164#section-4.1.1

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

Typically syslog events sent over the network start with a <number> containing information about so called "facility" and severity of the event.  See https://datatracker.ietf.org/doc/html/rfc3164#section-4.1.1

jlsiri
Engager

Thank you!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Precisely, which log? Can you provide an example? (Anonymised as necessary.)

0 Karma
Get Updates on the Splunk Community!

BORE at .conf25

Boss Of Regular Expression (BORE) was an interactive session run again this year at .conf25 by the brilliant ...

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...