Getting Data In

Split data into sourcetypes based on syslog Facility code

Jason
Motivator

I'm about to help a client get some data split into different sourcetypes from syslog, based on a facility code set by the device.

Assuming I turn on no_priority_stripping in the udp input, is there a more elegant solution than just regexing off of _raw to split this out? Or are facility/priority codes not pulled out at index time?

Tags (2)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

They are not handled specially, so you'd need to use a regular expression against the _raw data.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

They are not handled specially, so you'd need to use a regular expression against the _raw data.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...