<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Has anyone experienced this squid error with splunk_recommended_squid log format? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Has-anyone-experienced-this-squid-error-with-splunk-recommended/m-p/659897#M111586</link>
    <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Fri, 06 Oct 2023 02:40:23 GMT</pubDate>
    <dc:creator>user4567654</dc:creator>
    <dc:date>2023-10-06T02:40:23Z</dc:date>
    <item>
      <title>Has anyone experienced this squid error with splunk_recommended_squid log format?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Has-anyone-experienced-this-squid-error-with-splunk-recommended/m-p/624260#M107347</link>
      <description>&lt;P&gt;i am running Squid 5.2 and having an issue adding the splunk_recommended_squid log format to my squid configuration.&amp;nbsp; Pulled the log format right out of the splunk documentation.&amp;nbsp; i'll paste it at the end of this message.&amp;nbsp; When i try and start squid with that log format, i get an error:&lt;BR /&gt;&lt;BR /&gt;" FATAL: Bungled /etc/squid/squid.conf line 11: logformat splunk_squid&amp;nbsp;%ts.%03tu logformat=splunk_recommended_squid duration=%tr src_ip=%&amp;gt;a src_port=%&amp;gt;p dest_ip=%&amp;lt;a dest_port=%&amp;lt;p user_ident="%[ui" user="%[un" local_time=[%tl] http_method=%rm request_method_from_client=%&amp;lt;rm request_method_to_server=%&amp;gt;rm url="%ru" http_referrer="%{Referer}&amp;gt;h" http_user_agent="%{User-Agent}&amp;gt;h" status=%&amp;gt;Hs vendor_action=%Ss dest_status=%Sh total_time_milliseconds=%&amp;lt;tt http_content_type="%mt" bytes=%st bytes_in=%&amp;gt;st bytes_out=%&amp;lt;st sni="%ssl::&amp;gt;sni"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't been able to find anything solid to help out with this.&amp;nbsp; has anyone else experienced this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;-Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 17:12:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Has-anyone-experienced-this-squid-error-with-splunk-recommended/m-p/624260#M107347</guid>
      <dc:creator>rsd0991</dc:creator>
      <dc:date>2022-12-14T17:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone experienced this squid error with splunk_recommended_squid log format?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Has-anyone-experienced-this-squid-error-with-splunk-recommended/m-p/658781#M111408</link>
      <description>&lt;P&gt;Yes, it has to do with a bad log format in Squid &lt;span class="lia-unicode-emoji" title=":angry_face:"&gt;😠&lt;/span&gt; and no one updated the docs. I solved via Squid docs and process of elimination. I can't seem to get the ssl::sni to work at all but this is all of the options without ssl::sni.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;logformat splunk_recommended_squid %ts.%03tu logformat=splunk_recommended_squid duration=%tr src_ip=%&amp;gt;a src_port=%&amp;gt;p dest_ip=%&amp;lt;a dest_port=%&amp;lt;p user_ident="%ui" user="%un" local_time=[%tl] http_method=%rm request_method_from_client=%&amp;lt;rm request_method_to_server=%&amp;gt;rm url="%ru" http_referrer="%{Referer}&amp;gt;h" http_user_agent="%{User-Agent}&amp;gt;h" status=%&amp;gt;Hs vendor_action=%Ss dest_status=%Sh total_time_milliseconds=%&amp;lt;tt http_content_type="%mt" bytes=%st bytes_in=%&amp;gt;st bytes_out=%&amp;lt;st&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 26 Sep 2023 17:52:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Has-anyone-experienced-this-squid-error-with-splunk-recommended/m-p/658781#M111408</guid>
      <dc:creator>Ludvik</dc:creator>
      <dc:date>2023-09-26T17:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone experienced this squid error with splunk_recommended_squid log format?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Has-anyone-experienced-this-squid-error-with-splunk-recommended/m-p/659897#M111586</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 02:40:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Has-anyone-experienced-this-squid-error-with-splunk-recommended/m-p/659897#M111586</guid>
      <dc:creator>user4567654</dc:creator>
      <dc:date>2023-10-06T02:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: Has anyone experienced this squid error with splunk_recommended_squid log format?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Has-anyone-experienced-this-squid-error-with-splunk-recommended/m-p/751031#M119280</link>
      <description>&lt;P&gt;Ty men , sooo helpful .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2025 12:17:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Has-anyone-experienced-this-squid-error-with-splunk-recommended/m-p/751031#M119280</guid>
      <dc:creator>josevg1981</dc:creator>
      <dc:date>2025-08-05T12:17:05Z</dc:date>
    </item>
  </channel>
</rss>

