<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: apache access_common sourcetype not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/apache-access-common-sourcetype-not-working/m-p/20719#M3036</link>
    <description>&lt;P&gt;By default, Splunk should extract the standard fields for sourcetypes access_combined, access_combined_wcookie and access_common using the regex in transforms.conf called access-extractions.&lt;/P&gt;

&lt;P&gt;Since it's not parsing the data, it probably means that the regex isn't matching your log lines. If you paste a sample line, someone on answers should be able to point out why the extraction fails. Alternately, you can copy the extraction called access-extraction from etc/system/default/transforms.conf to etc/system/local/transforms.conf and tweak it to extract your fields.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jul 2010 00:48:47 GMT</pubDate>
    <dc:creator>Stephen_Sorkin</dc:creator>
    <dc:date>2010-07-28T00:48:47Z</dc:date>
    <item>
      <title>apache access_common sourcetype not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/apache-access-common-sourcetype-not-working/m-p/20718#M3035</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have recently configured a Splunk light forwarder to monitor an apache access_log.  I specified that the file being watched be recognized as an 'access_common' sourcetype.  We are using the standard apache output.&lt;/P&gt;

&lt;P&gt;Unfortunately, this pre-trained sourcetype does not seem to be parsing the fields in the log data.  Is there something else I need to configure?  I was under the impression that things like the IP address would be automatically assigned to a field...&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2010 06:46:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/apache-access-common-sourcetype-not-working/m-p/20718#M3035</guid>
      <dc:creator>sf_user_199</dc:creator>
      <dc:date>2010-07-27T06:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: apache access_common sourcetype not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/apache-access-common-sourcetype-not-working/m-p/20719#M3036</link>
      <description>&lt;P&gt;By default, Splunk should extract the standard fields for sourcetypes access_combined, access_combined_wcookie and access_common using the regex in transforms.conf called access-extractions.&lt;/P&gt;

&lt;P&gt;Since it's not parsing the data, it probably means that the regex isn't matching your log lines. If you paste a sample line, someone on answers should be able to point out why the extraction fails. Alternately, you can copy the extraction called access-extraction from etc/system/default/transforms.conf to etc/system/local/transforms.conf and tweak it to extract your fields.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2010 00:48:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/apache-access-common-sourcetype-not-working/m-p/20719#M3036</guid>
      <dc:creator>Stephen_Sorkin</dc:creator>
      <dc:date>2010-07-28T00:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: apache access_common sourcetype not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/apache-access-common-sourcetype-not-working/m-p/20720#M3037</link>
      <description>&lt;P&gt;Thanks - I moved the extraction to /local/transforms.conf and then removed one of the extractions - everything then worked.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2010 05:46:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/apache-access-common-sourcetype-not-working/m-p/20720#M3037</guid>
      <dc:creator>sf_user_199</dc:creator>
      <dc:date>2010-08-03T05:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: apache access_common sourcetype not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/apache-access-common-sourcetype-not-working/m-p/20721#M3038</link>
      <description>&lt;P&gt;which extraction did you remove?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2014 15:50:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/apache-access-common-sourcetype-not-working/m-p/20721#M3038</guid>
      <dc:creator>wrangler2x</dc:creator>
      <dc:date>2014-06-17T15:50:35Z</dc:date>
    </item>
  </channel>
</rss>

