Skip to content

Instantly share code, notes, and snippets.

@JasonConger
Created October 17, 2022 18:05
Show Gist options
  • Star 1 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save JasonConger/288a280a99091ce56e8817b635389fb5 to your computer and use it in GitHub Desktop.
Save JasonConger/288a280a99091ce56e8817b635389fb5 to your computer and use it in GitHub Desktop.
Azure NSG Flow Log - Splunk props.conf
[mscs:nsg:flow]
description = Azure NSG Flow Logs
LINE_BREAKER = (,|\[){"time"
category = Application
KV_MODE = json
SEDCMD-remove_footer = s/\]}$//g
SEDCMD-remove_header = s/{"records":\[//g
SHOULD_LINEMERGE = false
TIME_PREFIX = time\":\"
TRUNCATE = 0
MAX_TIMESTAMP_LOOKAHEAD = 32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment