<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with monitoring logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-logs/m-p/672111#M112603</link>
    <description>&lt;P&gt;Hey Guys,&lt;/P&gt;&lt;P&gt;I have a node js application and I used Winston to print out the log for our application. Ex(logger.info({responseStatus:200}). I am not using a log file and just simply printing out the log. I am not quite sure what's causing the issue here. The log event is working fine in other environments and displaying in the separate event log, so I can keep track of the event field name. But in the production environment, my logs are mixed with console.log and treated as one event instead. It looks something like this right here. (Just an example, but looks similar).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sambaing_0-1702796946184.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28554iFB241C759B9F1F80/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Sambaing_0-1702796946184.png" alt="Sambaing_0-1702796946184.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Sambaing_0-1702796946184.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am new to Splunk Enterprise, and I am not quite sure where my configuration file is located. It's ok if there's no solution, but I would like to&amp;nbsp;hear some advice from the expert from Splunk, on what may be causing this happening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 17 Dec 2023 07:16:02 GMT</pubDate>
    <dc:creator>Sambaing</dc:creator>
    <dc:date>2023-12-17T07:16:02Z</dc:date>
    <item>
      <title>Issue with monitoring logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-logs/m-p/672111#M112603</link>
      <description>&lt;P&gt;Hey Guys,&lt;/P&gt;&lt;P&gt;I have a node js application and I used Winston to print out the log for our application. Ex(logger.info({responseStatus:200}). I am not using a log file and just simply printing out the log. I am not quite sure what's causing the issue here. The log event is working fine in other environments and displaying in the separate event log, so I can keep track of the event field name. But in the production environment, my logs are mixed with console.log and treated as one event instead. It looks something like this right here. (Just an example, but looks similar).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sambaing_0-1702796946184.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28554iFB241C759B9F1F80/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Sambaing_0-1702796946184.png" alt="Sambaing_0-1702796946184.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Sambaing_0-1702796946184.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am new to Splunk Enterprise, and I am not quite sure where my configuration file is located. It's ok if there's no solution, but I would like to&amp;nbsp;hear some advice from the expert from Splunk, on what may be causing this happening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Dec 2023 07:16:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-logs/m-p/672111#M112603</guid>
      <dc:creator>Sambaing</dc:creator>
      <dc:date>2023-12-17T07:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with monitoring logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-logs/m-p/672181#M112606</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263403"&gt;@Sambaing&lt;/a&gt;&amp;nbsp;how to index these logs? Maybe your "source" field is not correctly defined.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2023 11:05:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-monitoring-logs/m-p/672181#M112606</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2023-12-18T11:05:38Z</dc:date>
    </item>
  </channel>
</rss>

