diff --git a/package/etc/conf.d/destinations/splunk_hec_debug.conf b/package/etc/conf.d/destinations/splunk_hec_debug.conf new file mode 100644 index 0000000..e5e6714 --- /dev/null +++ b/package/etc/conf.d/destinations/splunk_hec_debug.conf @@ -0,0 +1,14 @@ +destination d_hec_debug { + file("/opt/syslog-ng/var/archive/${.splunk.sourcetype}/${HOST}/$YEAR-$MONTH-$DAY-message.log" + template("curl -k -u \"sc4s HEC debug:$(env SPLUNK_HEC_TOKEN)\" \"$(env SPLUNK_HEC_URL)\" -d '$(format-json + time=$S_UNIXTIME.$S_MSEC + host=${HOST} + source=${.splunk.source} + sourcetype=${.splunk.sourcetype} + index=${.splunk.index} + event=$MSG + fields.*)'\n") +# file("/var/log/messages_syslog" + create_dirs(yes) + ); +};