Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why does syslog data delay when setting no_priority_stripping=true?

$
0
0
Hi, When I set no_priority_stripping = true in input.conf in Splunk server, my syslog data send to Splunk work but a very long delay of time. When I remove no_priority_stripping = true from input.conf. My unit sends syslog to Splunk in real-time. I do need to set no_priority_stripping = true, in order for me to use syslog_priority.csv lookup table. I need help to resolve this issue. Can you please point me in the right direction? Thanks, Matoula Senethavong

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>