All Apps and Add-ons

RFC5424 Syslog Add On is collecting HTTP Header information, but not showing the body of the message.

mgranger1
Path Finder

Hey Gang,

First, the basics. We are running a Splunk Enterprise 6.6.4 infrastructure on Red Hat Linux. We are attempting to collect data from a Cloud Foundry Log Drain, as documented here: https://docs.cloudfoundry.org/devguide/services/integrate-splunk.html

We have almost everything working properly, however, for some reason, we are receiving the HTTP header information (about 7 lines of it), but we are not receiving the body of the message. We have confirmed by using TCP packet captures that complete messages are being sent to my Splunk Heavy Forwarder, but when I look in Splunk at the index I've created for this purpose, the body of the messages are not being received.

I have several concerns. First, we are running the 1.1 version of the RFC5424_Syslog, and there haven't been any updates to this app since 2014. Second, the "Splunk Compatibility" of this app only goes through version 6.1 (which I'm sure was probably the current version back in 2014 when the last update was made).

Is anyone familiar with this app? Has anyone had an issue with losing the body of the message while using this app? Any help would be appreciated.

Sincerely,
Matthew Granger

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...