Skip to main content
Question

Can Cribl handle the Splunks functionality of assigning default fields dynamicaly?

  • March 11, 2025
  • 4 replies
  • 21 views

Does anyone knows, if Cribl can handle the Splunks functionality of assigning default fields dynamicaly withe the folowing line in the logs: `SPLUNK <metadata field>=<string> <metadata field>=<string> ...` https://docs.splunk.com/Documentation/Splunk/latest/Data/Assignmetadatatoeventsdynamically. If not I would go with a 2 step linebreaking process

4 replies

David Maislin

Eval function setting top level fields? Is that what you mean?


  • Author
  • New Participant
  • March 11, 2025

Its a different way to lable data with splunks metafields which should be processed on the first full splunk instance or in this case cribl. If I understand the process correctly First comes the Header ,the 1 to n events, which are then labeld with the headers metadata fieldshttps://helgeklein.com/blog/splunk-scripted-input-secrects/


Forum|alt.badge.img
  • Participating Frequently
  • March 11, 2025

Because we just discussed this <@U01C35EMQ01&gt; - it's HEADER_MODE in props.conf and e.g. UberAgent uses this


David Maislin

If events show up with that format Cribl could pull those fields out with Regex, Eval or Parser, cleanup the event and pass to Splunk cooked and ready to go.