We have updated our Terms of Service, Code of Conduct, and Addendum.

Can Cribl handle the Splunks functionality of assigning default fields dynamicaly?

Options

Does anyone knows, if Cribl can handle the Splunks functionality of assigning default fields dynamicaly withe the folowing line in the logs: `SPLUNK <metadata field>=<string> <metadata field>=<string> ...` https://docs.splunk.com/Documentation/Splunk/latest/Data/Assignmetadatatoeventsdynamically. If not I would go with a 2 step linebreaking process

Answers