You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
|indexedFields|array| IndexedFields are the list of fields to be indexed by Splunk, increase storage usage, they should be used sparingly and only for high-value fields that provide significant search benefits.
3153
+
Nested fields are flattened into top-level fields.
3154
+
Field paths are joined using dot notation, and unsupported characters are replaced with underscores (_).
3155
+
Non-string values are automatically converted to strings (e.g., 3 → "3", true → "true").
|source|string| Source identifies the origin of a log event.
3171
+
The Source can be a combination of static and dynamic values consisting of field paths followed by `||` followed by another field path or a static value.
3172
+
A dynamic value is encased in single curly brackets `{}` and MUST end with a static fallback value separated with `||`.
3173
+
Static values can only contain alphanumeric characters along with dashes, underscores, dots and forward slashes.
3174
+
If not specified will be detected according to .log_source and .log_type value.
3175
+
Details see in: docs/features/logforwarding/outputs/splunk-forwarding.adoc
The Facility can be a combination of static and dynamic values consisting of field paths followed by `||` followed by another field path or a static value.
3304
+
A dynamic value is encased in single curly brackets `{}` and MUST end with a static fallback value separated with `||`.
3305
+
3306
+
Static values can only contain alphanumeric characters along with dashes, underscores, dots and forward slashes.
3307
+
3308
+
Example:
3309
+
3310
+
1. {.foo||"user"}
3311
+
3258
3312
|msgId|string| MsgId is MSGID part of the syslog-msg header. This supports template syntax to allow dynamic per-event values.
3259
3313
3260
3314
The MsgId can be a combination of static and dynamic values consisting of field paths followed by `||` followed by another field path or a static value.
@@ -3321,6 +3375,15 @@ The value can be a decimal integer or one of these case-insensitive keywords:
The Severity can be a combination of static and dynamic values consisting of field paths followed by `||` followed by another field path or a static value.
3379
+
A dynamic value is encased in single curly brackets `{}` and MUST end with a static fallback value separated with `||`.
3380
+
3381
+
Static values can only contain alphanumeric characters along with dashes, underscores, dots and forward slashes.
3382
+
3383
+
Example:
3384
+
3385
+
1. {.foo||"Error"}
3386
+
3324
3387
|tuning|object| Tuning specs tuning for the output
3325
3388
3326
3389
|url|string| An absolute URL, with a scheme. Valid schemes are: `tcp`, `tls`, `udp`
0 commit comments