Splunk Search

What is <14> we see in Splunk logs, each log starts with <14> what does it pertain to ? can anyone answer this please?

jlsiri
Engager

<14> prefix is displayed in splunk logs, what does it mean, why is it displayed? Can anyone answer this question please?

0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

Typically syslog events sent over the network start with a <number> containing information about so called "facility" and severity of the event.  See https://datatracker.ietf.org/doc/html/rfc3164#section-4.1.1

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

Typically syslog events sent over the network start with a <number> containing information about so called "facility" and severity of the event.  See https://datatracker.ietf.org/doc/html/rfc3164#section-4.1.1

jlsiri
Engager

Thank you!

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Precisely, which log? Can you provide an example? (Anonymised as necessary.)

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...