Getting Data In

Why props.conf not getting picked up while ingesting data through HEC, /event endpoint?

neha898
New Member

Why props.conf not getting picked up while ingesting data through HEC, /event endpoint?

0 Karma
1 Solution

starcher
SplunkTrust
SplunkTrust

Only raw gets sent through the parsing queue. Using event presumes you are properly formatting your event in JSON and the JSON extraction handles everything. This is expected behavior.

View solution in original post

starcher
SplunkTrust
SplunkTrust

Only raw gets sent through the parsing queue. Using event presumes you are properly formatting your event in JSON and the JSON extraction handles everything. This is expected behavior.

neha898
New Member

I guess this is the confirmation I was looking for, so docker container logs should be ingested into SPlunk via the raw endpoint if we want to parse them at Splunk end.

0 Karma

starcher
SplunkTrust
SplunkTrust

keep in mind search time extractions are different than say even breaking and time stamping at the HF where HEC runs. so for the HF yes that is as I said and you'd need to be on raw.

0 Karma

neha898
New Member

Thanks a lot @starcher

0 Karma

xavierashe
Contributor

Let me ask a clairifying question. Are you collecting event through a HEC input on a heavy fowarder, and it doesn't seem to apply your props config? Can you post a sample event and your props.conf?

0 Karma

neha898
New Member

Yes, I am trying to collect events via HEC. Splunk is smartly formatting the timestamp, issue is that each exception form docker is getting posted as a separate event on a new line preceded by a containerid. My main doubt is that does props.conf on HF get picked up for HEC collector/event endpoint? I read on my other answers on this forum that /event endpoint doesn't pickup props and transforms processing.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...