Splunk Search

What is <14> we see in Splunk logs, each log starts with <14> what does it pertain to ? can anyone answer this please?

jlsiri
Engager

<14> prefix is displayed in splunk logs, what does it mean, why is it displayed? Can anyone answer this question please?

0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

Typically syslog events sent over the network start with a <number> containing information about so called "facility" and severity of the event.  See https://datatracker.ietf.org/doc/html/rfc3164#section-4.1.1

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

Typically syslog events sent over the network start with a <number> containing information about so called "facility" and severity of the event.  See https://datatracker.ietf.org/doc/html/rfc3164#section-4.1.1

jlsiri
Engager

Thank you!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Precisely, which log? Can you provide an example? (Anonymised as necessary.)

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...