Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

The events are not paring

$
0
0
Hi, I am using Expanded Snare syslog app in HF. But the problem here is the data is not getting parsed as per the props.conf in the app. Do we have to install this app in indexers as well ? OR HF will do the parsing before sending the logs to indexers? Please help!!

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>