|
I'm trying to set a custom archive processor. Is this still supported in Splunk 4.1? The documentation is contradictory. From props.conf.spec, the 2 parameters which both need to be set are
I can't get the archive processor to activate. Has anyone does this successfully? |
|
I looked through I think an example may make more sense then the paragraph above.
What I don't get is this: What's the need for all the different "preprocess-*" sourcetypes? I mean, why not just create a single |
|
Seems to be an old post but for those who are looking for it.. The purpose was to read some binary logs using archive processor. This configuration worked:
not sure sourcetype is mandatory to get this working. I was able to use invalid_cause under source::. Actually this is the only way it works for me. |
