Documentation:
3.2.2
The best way to index log4j files is to set up a standard log4j-syslog appender on your log4j host. Then configure the Splunk Server's properties to strip the syslog header prior to other processing, so Splunk doesn't think the logs are single-line syslog entries.
See the entry on stripping syslog headers for instructions on stripping the syslog headers.
Comments
No comments have been submitted.