<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for IBM WebSphere Application Server: How to configure the add-on to read from syslog server where rsyslog has forwarded the files? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-IBM-WebSphere-Application-Server-How-to/m-p/296822#M35473</link>
    <description>&lt;P&gt;@john.glasscock - Did the answer provided by goodsellt help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 20 Mar 2017 00:40:58 GMT</pubDate>
    <dc:creator>aaraneta_splunk</dc:creator>
    <dc:date>2017-03-20T00:40:58Z</dc:date>
    <item>
      <title>Splunk Add-on for IBM WebSphere Application Server: How to configure the add-on to read from syslog server where rsyslog has forwarded the files?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-IBM-WebSphere-Application-Server-How-to/m-p/296820#M35471</link>
      <description>&lt;P&gt;The Websphere admin has rsyslog the files over to a syslog server.   I am having issues configuring the Splunk Add-on for IBM WebSphere Application Server to pull the log files from the directory.  Normally, I would just setup a monitor stanza, but this Add-on doesn't seem to like it.  Any help would be appreciated.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 19:22:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-IBM-WebSphere-Application-Server-How-to/m-p/296820#M35471</guid>
      <dc:creator>john_glasscock</dc:creator>
      <dc:date>2017-02-13T19:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for IBM WebSphere Application Server: How to configure the add-on to read from syslog server where rsyslog has forwarded the files?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-IBM-WebSphere-Application-Server-How-to/m-p/296821#M35472</link>
      <description>&lt;P&gt;Since the addon probably is expecting the native log file lines and you're probably getting a syslog header attached to your lines, you'll likely to do something like this:&lt;BR /&gt;
- Create a dummy sourcetype like "ibm-websphere-syslog" and monitor your rsyslog files with that.&lt;BR /&gt;
- In the dummy sourcetype, setup a props and transforms so that it seds out the syslog header, then transforms the line to the "proper" ibm websphere sourcetype from the addon. &lt;BR /&gt;
- Verify that your data is being properly parsed as the real sourcetype and the fields expected from the addon are appearing.&lt;/P&gt;

&lt;P&gt;You could also redo the props.conf and transforms.conf statements to account for your syslog header and throw them in the local dir of the addon.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 21:14:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-IBM-WebSphere-Application-Server-How-to/m-p/296821#M35472</guid>
      <dc:creator>goodsellt</dc:creator>
      <dc:date>2017-02-13T21:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for IBM WebSphere Application Server: How to configure the add-on to read from syslog server where rsyslog has forwarded the files?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-IBM-WebSphere-Application-Server-How-to/m-p/296822#M35473</link>
      <description>&lt;P&gt;@john.glasscock - Did the answer provided by goodsellt help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2017 00:40:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-IBM-WebSphere-Application-Server-How-to/m-p/296822#M35473</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2017-03-20T00:40:58Z</dc:date>
    </item>
  </channel>
</rss>

