<?xml version="1.0" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
	<channel>
		<title>Splunk Base : SplunkAdministration : #2846</title>
		<link>http://www.splunk.com/support/forum:SplunkAdministration/2846</link>
		<description></description>
		<pubDate>Sun, 21 Mar 2010 15:41:55 PDT</pubDate>
		<lastBuildDate>Sun, 21 Mar 2010 15:41:55 PDT</lastBuildDate>
		<language>en-us</language>
		<copyright>http://creativecommons.org/licenses/by-nc-nd/2.5/</copyright>
		<item>
			<title>syslog tcp vs udp input + netscreen</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/2846/9106</link>
			<description>&lt;p&gt;Per &lt;a href=&quot;http://www.splunk.com/base/Documentation/latest/Admin/NetworkPorts#inputs.conf&quot;&gt;http://www.splunk.com/base/Documentation/latest/Admin/NetworkPorts#inputs.conf&lt;/a&gt;:&lt;/p&gt;

&lt;p&gt;no_priority_stripping = true | false&lt;/p&gt;

&lt;p&gt;* If this attribute is set to true, then Splunk does NOT strip the &amp;lt;priority&amp;gt; syslog field from received events.&lt;br /&gt;
    * Otherwise, Splunk strips syslog priority from events.&lt;/p&gt;

&lt;p&gt;no_appending_timestamp = true&lt;/p&gt;

&lt;p&gt;* If this attribute is set to true, then Splunk does NOT append a timestamp and host to received events.&lt;br /&gt;
    * Note: Do NOT include this key at all if you want to append timestamp and host to received events.&lt;/p&gt;

&lt;p&gt;linux-messages-syslog sourcetype tells splunk to do the following processing ($SPLUNK_HOME/etc/system/default/props.conf):&lt;/p&gt;

&lt;p&gt;[linux_messages_syslog]&lt;br /&gt;
pulldown_type = true &lt;br /&gt;
MAX_TIMESTAMP_LOOKAHEAD = 32&lt;br /&gt;
TIME_FORMAT = %b %d %H:%M:%S&lt;br /&gt;
TRANSFORMS = syslog-host&lt;br /&gt;
REPORT-syslog = syslog-extractions&lt;br /&gt;
SHOULD_LINEMERGE = False&lt;/p&gt;

</description>
			<pubDate>Fri, 12 Jun 2009 10:10:45 PDT</pubDate>
			<author>araitz</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/2846/9106</guid>
		</item>
		<item>
			<title>syslog tcp vs udp input + netscreen</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/2846/9098</link>
			<description>&lt;p&gt;Hi,&lt;/p&gt;

&lt;p&gt;We have started some practical work with evaluating Splunk (3.4.10) and I have questions regarding details.&lt;/p&gt;

&lt;p&gt;1: Splunk tcp input from Linux syslog clients compared with udp input yields different output:&lt;/p&gt;

&lt;p&gt;tcp:&lt;br /&gt;
&amp;lt;83&amp;gt;Jun  5 10:34:37 uo000156 agetty[26028]: /dev/xvc0: No such file or directory&lt;br /&gt;
udp:&lt;br /&gt;
Jun  1 11:05:51 up000073.abrakdabra.com Jun  1 11:05:51 up000073 syslog-ng[19358]: SIGHUP received, restarting syslog-ng&lt;/p&gt;

&lt;p&gt;Furthermore when loading syslog input from Juniper Netscreen to the tcp listener there is no recognition of messages start and stop, they are auto truncated (by length  I assume) and what should be separate messages are presented as one which can be truncated and continue in the next message. Sending data to the udp listener yields more &amp;quot;normal&amp;quot; output with messages separated as they should. I found a Netscreen application , downloaded, installed and enabled it, but could not notice any differences. Probably because I have not yet realized what configration entries that should be changed.&lt;/p&gt;

&lt;p&gt;I have looked at &lt;a href=&quot;http://interop.demo.splunk.com/&quot; onclick=&quot;window.open(this.href, '_blank'); return false;&quot;&gt;http://interop.demo.splunk.com/&lt;/a&gt; (Splunk 3.4.5) and this site does not display tcp input with the pri field. There is also data from Juniper Netscreen via tcp and this information is presented nicely and what you would expect as normal output.&lt;/p&gt;

&lt;p&gt;Is this difference between tcp and udp input considered as normal ? I assume that there might be some additional configuration to accomplish the same result as from the demo site ( &lt;a href=&quot;http://interop.demo.splunk.com/&quot; onclick=&quot;window.open(this.href, '_blank'); return false;&quot;&gt;http://interop.demo.splunk.com/&lt;/a&gt;). Is there any way to get information and/or config files regarding this ?&lt;/p&gt;

&lt;p&gt;2: What is the practical difference when selecting linux-messages-syslog compared with syslog when specifying source type ?&lt;/p&gt;

&lt;p&gt;linux-messages-syslog:&lt;br /&gt;
&amp;lt;4&amp;gt;May 29 17:45:35 up000073 kernel: SFW2-INext-DROP-DEFLT IN=eth0 OUT= MAC=01:00:5e:00:00:01:00:01:30:5f:c9:00:08:00 SRC=107.21.24.251 DST=224.0.0.1 LEN=28 TOS=0x00 PREC=0xC0 TTL=1 ID=42110 PROTO=2&lt;/p&gt;

&lt;p&gt;syslog:&lt;br /&gt;
&amp;lt;83&amp;gt;Jun  5 10:34:37 uo000156 agetty[26028]: /dev/xvc0: No such file or directory&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;BR,&lt;br /&gt;
Anders&lt;/p&gt;

</description>
			<pubDate>Fri, 12 Jun 2009 07:23:21 PDT</pubDate>
			<author>anderss</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/2846/9098</guid>
		</item>
	</channel>
</rss>
