<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create your own add-on? | How to parse unusual logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-your-own-add-on-How-to-parse-unusual-logs/m-p/687962#M114592</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/267362"&gt;@splunky_diamond&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it's always a pleasure!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Sun, 19 May 2024 10:00:10 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-05-19T10:00:10Z</dc:date>
    <item>
      <title>How to create your own add-on? | How to parse unusual logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-your-own-add-on-How-to-parse-unusual-logs/m-p/687958#M114589</link>
      <description>&lt;P&gt;Hello Splunkers!&lt;BR /&gt;&lt;BR /&gt;I am collecting logs from Fudo PAM for which I haven't found any suitable existing add-on on the Splunk Base website. The logs are being collected over syslog, yet the regular "syslog" sourcetype doesn't suit the events coming from my source. I was searching the web for some tutorials on how to create your own add-on in Splunk in order to parse the unusual logs like in my case, but I haven't found any.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Could someone please help me with that? Does anyone have any tutorial or guide on how to create your own parser, or can maybe explain what is needed for that, in case it's not a difficult task?&lt;BR /&gt;&lt;BR /&gt;If someone decides to provide answer themselves, by explaining how to create your own add-on, I would really appreciate detailed description that will involve such notes as: required skills, difficulty, how long it will take, and whether it's the best practice in such situations or there are more efficient ways.&lt;BR /&gt;&lt;BR /&gt;Again, the main goal for me is to get my logs from Fudo PAM (coming over syslog) parsed properly.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you for taking your time reading my post and replying to it &lt;span class="lia-unicode-emoji" title=":red_heart:"&gt;❤️&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 19 May 2024 07:52:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-your-own-add-on-How-to-parse-unusual-logs/m-p/687958#M114589</guid>
      <dc:creator>splunky_diamond</dc:creator>
      <dc:date>2024-05-19T07:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to create your own add-on? | How to parse unusual logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-your-own-add-on-How-to-parse-unusual-logs/m-p/687960#M114590</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/267362"&gt;@splunky_diamond&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the best guide in ad-on creation is the Splunk Add-On Builder app (&lt;A href="https://splunkbase.splunk.com/app/2962" target="_blank"&gt;https://splunkbase.splunk.com/app/2962&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;It guides you in the creation and in the normalization of your data to have a CIM compliant data flow that you can use also in ES or ITSI.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 19 May 2024 09:18:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-your-own-add-on-How-to-parse-unusual-logs/m-p/687960#M114590</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-05-19T09:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to create your own add-on? | How to parse unusual logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-your-own-add-on-How-to-parse-unusual-logs/m-p/687961#M114591</link>
      <description>&lt;P&gt;Thank you very much&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;You never fail to deliver best solutions for splunk newbies like me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 19 May 2024 09:41:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-your-own-add-on-How-to-parse-unusual-logs/m-p/687961#M114591</guid>
      <dc:creator>splunky_diamond</dc:creator>
      <dc:date>2024-05-19T09:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to create your own add-on? | How to parse unusual logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-your-own-add-on-How-to-parse-unusual-logs/m-p/687962#M114592</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/267362"&gt;@splunky_diamond&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it's always a pleasure!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 19 May 2024 10:00:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-your-own-add-on-How-to-parse-unusual-logs/m-p/687962#M114592</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-05-19T10:00:10Z</dc:date>
    </item>
  </channel>
</rss>

