Hello, I have some issues writing PROPS configuration for XML source file. Sample XML events (2 Events) are given below. Any help will be highly appreciated. Thank you so much. TIME_PREFIX= T...
Hello, How I would write my Props Configuration (Tme Prefix, Time Format, LINE/EVENT Breaker...etc) for following HTML data source. A segment of HTML data from source file provided&n...
Hello, I have issues to write PROPS configuration file for following csv file (please see screenshot below for sample data) with No Header on it. Five columns showed in the screenshot are all v...
...rite PROPS configuration file for that csv source file, since I am getting some error messages in timestamps and some extra columns at the beginning of events. Any help will be h...
...tanza is:
[monitor:///opt/inboundlogs/10.10.10.10/*_syslog.log]
host = 10.10.10.10
disabled = false
source = $HOSTNAME 10.10.10.10
sourcetype = vm_app
index = app_foo
The file name is /opt/i...
...plunk server split the events up correctly at time of indexing.
Is there an app I need to install to configure a receiver?
Should I have multiple receivers for different source types? Or do I m...
Hello, I am getting some error messages within my PROPS Configuration file to parse timestamp data. The sample file/event, my props configuration, and error message are giving below. Any help will b...
Hello, I have some issues writing a PROPS configuration file for the following source data stored in text file. I also used TIMESTAMP_FIELDS= timeStamp there, to have field v...
...ecords have the client's IP address (or the source IP) in them.
Is there a way to configure Splunk so that it records the client IP in the record metadata? I would like the server to obtain this i...
Hello,
We would like to match all sources except the ones including /splunk/ in props.conf.
Example: No match for /opt/splunk/var/log/splunk/metrics.log and /opt/splunk/var/log/splunk/s...