Hi everyone. I am still learning Splunk so that I will need your assistance on this, please. I am currently working on a PoC where our firewalls are sending traffic logs to Splunk. In order to shorten the size of data being ingested into Splunk I would like to know if there is an option to remove “variable” names from traffic being transmitted. In summary, this is a typical traffic log that we receive from our firewalls in order to ingest it into Splunk: Instead, we would like to ingest only "values" from each “key/value” pair. In this case, instead of time=17:28:50 devname=”my3700d”, only 17:28:50 “my3700d” would be ingested. Could you guys please assist me on this issue? Thank you very much. Fmandelli
... View more