Dear sir
I have read all information on the Splunk answers. but I couldnt find any solutionn for my situation. I am new in the world of splunk and splunk is running in test lab. I can forward syslog to splunkm but splunk remove priority fields from syslog. I have add the following code in the inpust.conf file and restart the splunk, but it didnt solved my problem.
C:\Program Files\Splunk\etc\system\local\inputs.conf
[udp://514]
no_priority_stripping = true
I tried also this location:
C:\Program Files\Splunk\etc\apps\search\local\inputs.conf
[udp://514]
no_priority_stripping = true
Would anyone please tell me if am i configuring in the worng place?
If anyone can help me I would apprecaite that.
thanks in advance
Best Rrgards,
Herat
... View more