All,
My first time messing with data manipulation at the heavy forwarder tier. Specifically looking to CIM a field my developers can't fix at code. Essentially quick sub elapsedTime to duration.
Version: Splunk 6.32/UF 6.24
Linux CentOS 6.x
props.conf
[log4j]
SED-alter = y/elapsedTime/duration/
↧