Splunk Mail2000 Log Source Type

vim /opt/splunk/etc/system/local/props.conf


[mail2000_access]
NO_BINARY_CHECK = 1
pulldown_type = 1

[mail2000_imap]
NO_BINARY_CHECK = 1
pulldown_type = 1

[mail2000_imss]
NO_BINARY_CHECK = 1
pulldown_type = 1

[mail2000_login]
NO_BINARY_CHECK = 1
pulldown_type = 1

[mail2000_mailer]
NO_BINARY_CHECK = 1
pulldown_type = 1

[mail2000_pop3]
NO_BINARY_CHECK = 1
pulldown_type = 1

[mail2000_smtp]
NO_BINARY_CHECK = 1
pulldown_type = 1

[mail2000_imss]
NO_BINARY_CHECK = 1
pulldown_type = 1
This entry was posted in Linux, Splunk. Bookmark the permalink.

One Response to Splunk Mail2000 Log Source Type

  1. 可以先讓 Splunk Preview 幫忙識別適合哪一種 SourceType

Comments are closed.