Documentation: 3.1.3
Print Version Contents
This page last updated: 11/27/07 10:11am

log4j

The best way to index log4j files is to set up a standard log4j-syslog appender on your log4j host. Then configure the Splunk Server's properties to strip the syslog header prior to other processing, so Splunk doesn't think the logs are single-line syslog entries.

See the entry on stripping syslog headers for instructions on stripping the syslog headers.

External Links

Previous: Add binary files    |    Next: Dynamic metadata assignment

Comments

No comments have been submitted.

Log in to comment.