Getting Data In

Why props.conf not getting picked up while ingesting data through HEC, /event endpoint?

neha898
New Member

Why props.conf not getting picked up while ingesting data through HEC, /event endpoint?

0 Karma
1 Solution

starcher
Influencer

Only raw gets sent through the parsing queue. Using event presumes you are properly formatting your event in JSON and the JSON extraction handles everything. This is expected behavior.

View solution in original post

starcher
Influencer

Only raw gets sent through the parsing queue. Using event presumes you are properly formatting your event in JSON and the JSON extraction handles everything. This is expected behavior.

neha898
New Member

I guess this is the confirmation I was looking for, so docker container logs should be ingested into SPlunk via the raw endpoint if we want to parse them at Splunk end.

0 Karma

starcher
Influencer

keep in mind search time extractions are different than say even breaking and time stamping at the HF where HEC runs. so for the HF yes that is as I said and you'd need to be on raw.

0 Karma

neha898
New Member

Thanks a lot @starcher

0 Karma

xavierashe
Contributor

Let me ask a clairifying question. Are you collecting event through a HEC input on a heavy fowarder, and it doesn't seem to apply your props config? Can you post a sample event and your props.conf?

0 Karma

neha898
New Member

Yes, I am trying to collect events via HEC. Splunk is smartly formatting the timestamp, issue is that each exception form docker is getting posted as a separate event on a new line preceded by a containerid. My main doubt is that does props.conf on HF get picked up for HEC collector/event endpoint? I read on my other answers on this forum that /event endpoint doesn't pickup props and transforms processing.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...