Getting Data In

Splunk onboarding field values mistake

splunklearner
Path Finder

We are trying to onboard data from F5 WAF devices to our splunk. F5 team sending it by key value pairs. And one of them is "headers:xxxxxxxxx" (nearly 40 words). When data is getting  onboarded and we are checking in splunk web, below the table format headers field is not capturing correctly. It is giving some other value. Same with other field where its value is getting truncated. Please help me in this case.

Labels (1)
0 Karma

dural_yyz
Builder

https://docs.splunk.com/Documentation/Splunk/9.3.0/Admin/Propsconf#Structured_Data_Header_Extraction...

 

Start here and see what you can find, otherwise please provide your props.conf configuration if possible so we can actually see what is being attempted vs an example of the actual output.  A sample of the log helps when deciphering how your existing props.conf is interacting with the data.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...