<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Logging for Splunk - Best Practices or Tips? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Logging-for-Splunk-Best-Practices-or-Tips/m-p/20219#M2937</link>
    <description>&lt;P&gt;Just getting started with Splunk. I'm looking to get better instrumentation and visibility into our systems. In some cases this could be for debugging, in other cases for audit-trail type uses. &lt;/P&gt;

&lt;P&gt;Since I'm going to (re)write all of our logging code in these systems, does anybody have any suggestions? &lt;/P&gt;

&lt;P&gt;Certainly one thing I'm looking to accomplish is "joining" events across log files as they flow through our system. Aside from that, my use cases seem pretty basic. But since i'm in this position where I can design my logs just for splunk I thought people who've been doing this for a while could have some tips that might make my life easier later on. &lt;/P&gt;

&lt;P&gt;Thanks!&lt;BR /&gt;
Shane&lt;/P&gt;</description>
    <pubDate>Sat, 28 Jul 2012 00:06:42 GMT</pubDate>
    <dc:creator>shaneharter</dc:creator>
    <dc:date>2012-07-28T00:06:42Z</dc:date>
    <item>
      <title>Logging for Splunk - Best Practices or Tips?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logging-for-Splunk-Best-Practices-or-Tips/m-p/20219#M2937</link>
      <description>&lt;P&gt;Just getting started with Splunk. I'm looking to get better instrumentation and visibility into our systems. In some cases this could be for debugging, in other cases for audit-trail type uses. &lt;/P&gt;

&lt;P&gt;Since I'm going to (re)write all of our logging code in these systems, does anybody have any suggestions? &lt;/P&gt;

&lt;P&gt;Certainly one thing I'm looking to accomplish is "joining" events across log files as they flow through our system. Aside from that, my use cases seem pretty basic. But since i'm in this position where I can design my logs just for splunk I thought people who've been doing this for a while could have some tips that might make my life easier later on. &lt;/P&gt;

&lt;P&gt;Thanks!&lt;BR /&gt;
Shane&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jul 2012 00:06:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logging-for-Splunk-Best-Practices-or-Tips/m-p/20219#M2937</guid>
      <dc:creator>shaneharter</dc:creator>
      <dc:date>2012-07-28T00:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: Logging for Splunk - Best Practices or Tips?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logging-for-Splunk-Best-Practices-or-Tips/m-p/20220#M2938</link>
      <description>&lt;P&gt;This is a pretty good starting point: &lt;A href="http://dev.splunk.com/view/logging-with-splunk/SP-CAAADP5"&gt;http://dev.splunk.com/view/logging-with-splunk/SP-CAAADP5&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;What I can add from my experience is that printing the following things in every event is really valuable:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;The severity of the event (ie. DEBUG/INFO/WARN/ERROR)&lt;/LI&gt;
&lt;LI&gt;A thread identifier (Some sequential or random string that identifies the current thread)&lt;/LI&gt;
&lt;LI&gt;The source of the log event (ie. class, function or filename)&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sat, 28 Jul 2012 00:55:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logging-for-Splunk-Best-Practices-or-Tips/m-p/20220#M2938</guid>
      <dc:creator>ziegfried</dc:creator>
      <dc:date>2012-07-28T00:55:43Z</dc:date>
    </item>
    <item>
      <title>Re: Logging for Splunk - Best Practices or Tips?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logging-for-Splunk-Best-Practices-or-Tips/m-p/20221#M2939</link>
      <description>&lt;P&gt;The identifier is a great point but missed by some and when combined with transaction you have a great tool for troubleshooting and debugging process/thread/event specific execution&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jul 2012 09:48:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logging-for-Splunk-Best-Practices-or-Tips/m-p/20221#M2939</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-07-28T09:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: Logging for Splunk - Best Practices or Tips?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logging-for-Splunk-Best-Practices-or-Tips/m-p/20222#M2940</link>
      <description>&lt;P&gt;The logging content referred to above is now here: &lt;A href="http://dev.splunk.com/view/logging/SP-CAAAFCK"&gt;http://dev.splunk.com/view/logging/SP-CAAAFCK&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2017 17:58:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logging-for-Splunk-Best-Practices-or-Tips/m-p/20222#M2940</guid>
      <dc:creator>mtevenan_splunk</dc:creator>
      <dc:date>2017-03-16T17:58:14Z</dc:date>
    </item>
  </channel>
</rss>

