Filip Slunecko 2012-10-16, 21:27
-Re: syslog source - sinks without datetime/hostname
Hari Shreedharan 2012-10-16, 22:00
The reason for this is that the Text serializer will only serialized the body of the event, and the syslog sources write the body of the syslog event into the body of the flume event. The hostname/timestamp/severity etc are added into the Flume Event headers. You could simply write a serializer which writes out this information in the same format as you expect and you will be able to see the headers in the files. You could use the Avro serializer to serialize it into avro too, which will make sure the headers are also written out.
Hope this helps.
On Tuesday, October 16, 2012 at 2:27 PM, Filip Slunecko wrote:
> I am trying to use syslog source and sink it to hdfs or fileroller.
> Everything is working, but "saved" logs are without timestamp and
> hostname information.
> Is it possible to force flume-ng to dump those information from syslog
> header togather with body lines?
> I am using flume-ng-agent-1.2.0+24.4-1.noarch from Cloudera repository.
Filip Slunecko 2012-10-16, 22:25
Hari Shreedharan 2012-10-16, 22:36
Roshan Naik 2012-10-16, 22:48
Bhaskar V. Karambelkar 2012-10-16, 23:24
Filip Slunecko 2012-11-03, 13:54
Hari Shreedharan 2012-10-16, 23:01
Roshan Naik 2012-10-16, 21:32