gzip
.event_sourcetype
.index
field. If the key is found, it will have precedence over the value set in event_index
.key_name record_accessor_pattern
.event
key in the payload sent to the HEC. It will also append the time of the record to a top level time
key.Splunk_Send_Raw On
in the plugin configuration, and add the metadata as keys/values in the record. Note: with Splunk_Send_Raw
enabled, you are responsible for creating and populating the event
section of the payload.splunk_send_raw
has been enabled, the user must take care to put all log details in the event field, and only specify fields known to Splunk in the top level event, if there is a mismatch, Splunk will return a HTTP error 400.Splunk_send_raw
option being enabled and formatting the message properly. This includes three specific operationsmetric_name:
to all metrics