<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Parse Log Messages in Security</title>
    <link>https://community.splunk.com/t5/Security/Parse-Log-Messages/m-p/62771#M2092</link>
    <description>&lt;P&gt;What do you mean by "parameters defined by Splunk"?&lt;/P&gt;

&lt;P&gt;Are you just trying to extract new fields?&lt;BR /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://www.splunk.com/base/Documentation/latest/User/ExtractNewFields" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/User/ExtractNewFields&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 
&lt;A href="http://www.splunk.com/base/Documentation/latest/User/InteractiveFieldExtractionExample" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/User/InteractiveFieldExtractionExample&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 02 Oct 2010 05:13:10 GMT</pubDate>
    <dc:creator>southeringtonp</dc:creator>
    <dc:date>2010-10-02T05:13:10Z</dc:date>
    <item>
      <title>Parse Log Messages</title>
      <link>https://community.splunk.com/t5/Security/Parse-Log-Messages/m-p/62770#M2091</link>
      <description>&lt;P&gt;I'm sending a series of events to Splunk with their own time stamp and username info that I built independently of Splunk. Is there any way to run or build a custom report such that I can use the data that I passed in as parameters, instead of only being able to choose from the parameters defined by Splunk?&lt;/P&gt;</description>
      <pubDate>Sat, 02 Oct 2010 05:04:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Parse-Log-Messages/m-p/62770#M2091</guid>
      <dc:creator>mspiegel</dc:creator>
      <dc:date>2010-10-02T05:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Parse Log Messages</title>
      <link>https://community.splunk.com/t5/Security/Parse-Log-Messages/m-p/62771#M2092</link>
      <description>&lt;P&gt;What do you mean by "parameters defined by Splunk"?&lt;/P&gt;

&lt;P&gt;Are you just trying to extract new fields?&lt;BR /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="http://www.splunk.com/base/Documentation/latest/User/ExtractNewFields" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/User/ExtractNewFields&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 
&lt;A href="http://www.splunk.com/base/Documentation/latest/User/InteractiveFieldExtractionExample" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/User/InteractiveFieldExtractionExample&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Oct 2010 05:13:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Parse-Log-Messages/m-p/62771#M2092</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2010-10-02T05:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Parse Log Messages</title>
      <link>https://community.splunk.com/t5/Security/Parse-Log-Messages/m-p/62772#M2093</link>
      <description>&lt;P&gt;This helped a lot, thank you. However, I'm still unable to search over time from the self-created timestamp that I tried to pass into my splunk log message. Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2010 05:12:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Parse-Log-Messages/m-p/62772#M2093</guid>
      <dc:creator>mspiegel</dc:creator>
      <dc:date>2010-10-05T05:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Parse Log Messages</title>
      <link>https://community.splunk.com/t5/Security/Parse-Log-Messages/m-p/62773#M2094</link>
      <description>&lt;P&gt;Splunk is pretty good about picking up on timestamps out-of-the box. Usually if it doesn't see it, that means the timestamp is in a nonstandard format, or there's something else earlier in the message that looks like a timestamp. Also, there's a limit to how far into an event Splunk will look by default. If you can post a few lines of (sanitized) sample data, people here will be better able to help. The docs have some good information too - take a look at &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/HowSplunkextractstimestamps"&gt;http://www.splunk.com/base/Documentation/latest/Admin/HowSplunkextractstimestamps&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2010 08:25:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Parse-Log-Messages/m-p/62773#M2094</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2010-10-05T08:25:06Z</dc:date>
    </item>
  </channel>
</rss>

