<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to extract txt format application logs into splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-txt-format-application-logs-into-splunk/m-p/590663#M103458</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244232"&gt;@pratikgujar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;ok, let me understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you have log data on another server than the Splunk server,&lt;/LI&gt;&lt;LI&gt;you already take these logs using an UF,&lt;/LI&gt;&lt;LI&gt;so you have these logs in Splunk,&lt;/LI&gt;&lt;LI&gt;you have to parse these logs (extract fields) to use them in searches;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;is this correct?&lt;/P&gt;&lt;P&gt;If this is your situation, if you could share your logs, highlighting the fields you want to parse I can hep you, otherwise, you could follow the hint of &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/90723"&gt;@diogofgm&lt;/a&gt;&amp;nbsp;and use the Interactive field extractor.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 24 Mar 2022 13:06:48 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-03-24T13:06:48Z</dc:date>
    <item>
      <title>How to extract txt format application logs into splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-txt-format-application-logs-into-splunk/m-p/590563#M103450</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;Need help for the below qery&lt;/P&gt;
&lt;P&gt;I have st of application logs and all are in text format which are genratng every day.&lt;/P&gt;
&lt;P&gt;So i need to send all those logs to the splunk with proper field extraction.&lt;/P&gt;
&lt;P&gt;Please assist.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 20:54:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-txt-format-application-logs-into-splunk/m-p/590563#M103450</guid>
      <dc:creator>pratikgujar</dc:creator>
      <dc:date>2022-03-25T20:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract txt format application logs into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-txt-format-application-logs-into-splunk/m-p/590604#M103452</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244232"&gt;@pratikgujar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have to read some documentation or see some videos about Splunk "getting data in" (&lt;A href="https://www.google.com/search?q=splunk+getting+data+in&amp;amp;rlz=1C1SQJL_itIT832IT832&amp;amp;oq=splunk+getting+data+in&amp;amp;aqs=chrome.0.69i19i59j0i19j69i59l2j69i60l3.4744j0j7&amp;amp;sourceid=chrome&amp;amp;ie=UTF-8" target="_blank"&gt;https://www.google.com/search?q=splunk+getting+data+in&amp;amp;rlz=1C1SQJL_itIT832IT832&amp;amp;oq=splunk+getting+data+in&amp;amp;aqs=chrome.0.69i19i59j0i19j69i59l2j69i60l3.4744j0j7&amp;amp;sourceid=chrome&amp;amp;ie=UTF-8&lt;/A&gt;) and Splunk search Tutorial (&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/WelcometotheSearchTutorial" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/WelcometotheSearchTutorial&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;Anyway, you have to configure the system where log files are stored, if it's the same system where Splunk is installed you can use the GUI to ingest these data [Settings -- Data inputs -- .Files &amp;amp; Directories], if the fiels are in another system, you have to install a Splunk universal Forwarder and configure it to take the logs and send them to Splunk.&lt;/P&gt;&lt;P&gt;When you have these logs on Splunk you have to extract (parse) the fields using regexes, I cannot help you more without having a sample of your data.&lt;/P&gt;&lt;P&gt;Anyway, my hint is to read documentation and/or see some video about getting data in and searching.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 08:02:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-txt-format-application-logs-into-splunk/m-p/590604#M103452</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-03-24T08:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract txt format application logs into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-txt-format-application-logs-into-splunk/m-p/590656#M103456</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;thanks for the comment.&lt;/P&gt;&lt;P&gt;I have gone through the document.But here my query is that I have bunch of application data that too colleting on one server and from there I am collecting the same with he help of UF.&lt;/P&gt;&lt;P&gt;But the data is not in CSV format its in text format and I need to mapp the fields for the same.Alhough its not in csv so facing challenges to exract fields.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 12:29:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-txt-format-application-logs-into-splunk/m-p/590656#M103456</guid>
      <dc:creator>pratikgujar</dc:creator>
      <dc:date>2022-03-24T12:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract txt format application logs into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-txt-format-application-logs-into-splunk/m-p/590658#M103457</link>
      <description>&lt;P&gt;Have you met the interactive field extractor? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/ExtractfieldsinteractivelywithIFX" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/ExtractfieldsinteractivelywithIFX&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 12:43:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-txt-format-application-logs-into-splunk/m-p/590658#M103457</guid>
      <dc:creator>diogofgm</dc:creator>
      <dc:date>2022-03-24T12:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract txt format application logs into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-txt-format-application-logs-into-splunk/m-p/590663#M103458</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244232"&gt;@pratikgujar&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;ok, let me understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you have log data on another server than the Splunk server,&lt;/LI&gt;&lt;LI&gt;you already take these logs using an UF,&lt;/LI&gt;&lt;LI&gt;so you have these logs in Splunk,&lt;/LI&gt;&lt;LI&gt;you have to parse these logs (extract fields) to use them in searches;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;is this correct?&lt;/P&gt;&lt;P&gt;If this is your situation, if you could share your logs, highlighting the fields you want to parse I can hep you, otherwise, you could follow the hint of &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/90723"&gt;@diogofgm&lt;/a&gt;&amp;nbsp;and use the Interactive field extractor.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 13:06:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-txt-format-application-logs-into-splunk/m-p/590663#M103458</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-03-24T13:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to extract txt format application logs into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-txt-format-application-logs-into-splunk/m-p/590790#M103487</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;Thanks for suggestions.&lt;/P&gt;&lt;P&gt;I Will follow the solution provided by&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/90723"&gt;@diogofgm&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 04:07:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-extract-txt-format-application-logs-into-splunk/m-p/590790#M103487</guid>
      <dc:creator>pratikgujar</dc:creator>
      <dc:date>2022-03-25T04:07:30Z</dc:date>
    </item>
  </channel>
</rss>

