<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cannot find sourcetype squid in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/cannot-find-sourcetype-squid/m-p/21509#M3206</link>
    <description>&lt;P&gt;thanks rroberts &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jul 2010 22:05:04 GMT</pubDate>
    <dc:creator>njathan</dc:creator>
    <dc:date>2010-07-30T22:05:04Z</dc:date>
    <item>
      <title>cannot find sourcetype squid</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/cannot-find-sourcetype-squid/m-p/21504#M3201</link>
      <description>&lt;P&gt;I am trying to analyse a squid access log for top 10 reports (top sources, top destinations, etc.)&lt;/P&gt;

&lt;P&gt;I imported the log file in
Manager » Data inputs » Files &amp;amp; Directories » Add New&lt;/P&gt;

&lt;P&gt;When i keep the sourcetype=automatic, it does not seem to identify the source destination etc fields... just bundles them into one huge field, which is useless.&lt;/P&gt;

&lt;P&gt;Elsewhere in this forum, i found someone's using sourcetype=squid_access. Where is this available for the latest version (4.1.4)? If not this, what is the best way of analysing squid logs in splunk?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2010 19:36:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/cannot-find-sourcetype-squid/m-p/21504#M3201</guid>
      <dc:creator>njathan</dc:creator>
      <dc:date>2010-07-28T19:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find sourcetype squid</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/cannot-find-sourcetype-squid/m-p/21505#M3202</link>
      <description>&lt;P&gt;When you set sourcetype to manual you should be able to type squid_access in the box below.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2010 20:45:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/cannot-find-sourcetype-squid/m-p/21505#M3202</guid>
      <dc:creator>rroberts</dc:creator>
      <dc:date>2010-07-28T20:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find sourcetype squid</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/cannot-find-sourcetype-squid/m-p/21506#M3203</link>
      <description>&lt;P&gt;the 'drop-down' list appears when i choose the 'From list' option in the 'Set sourcetype' section... Manual sourcetype does not give any listing...&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2010 22:49:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/cannot-find-sourcetype-squid/m-p/21506#M3203</guid>
      <dc:creator>njathan</dc:creator>
      <dc:date>2010-07-28T22:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find sourcetype squid</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/cannot-find-sourcetype-squid/m-p/21507#M3204</link>
      <description>&lt;P&gt;actually manually typing access_squid does not help in that fields like TCP_MISS/200, CONNECT, &lt;A href="http://mail.google.com" target="_blank"&gt;http://mail.google.com&lt;/A&gt; etc in the log dont get classified into separate fields. Tried the 'extract fields' options, but i am poor at regex, and would be helpful if there is a ready plugin that lets splunk categorize the fields accordingly. (Which is not happening right now.)&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:15:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/cannot-find-sourcetype-squid/m-p/21507#M3204</guid>
      <dc:creator>njathan</dc:creator>
      <dc:date>2020-09-28T09:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find sourcetype squid</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/cannot-find-sourcetype-squid/m-p/21508#M3205</link>
      <description>&lt;P&gt;I see what you mean now have you seen this doc? &lt;A href="http://www.splunk.com/wiki/Community:Field_extractions_for_Squid_data"&gt;http://www.splunk.com/wiki/Community:Field_extractions_for_Squid_data&lt;/A&gt;&lt;BR /&gt;
There is a props.conf and transforms.conf example for squid field extraction that might be helpful.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2010 04:07:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/cannot-find-sourcetype-squid/m-p/21508#M3205</guid>
      <dc:creator>rroberts</dc:creator>
      <dc:date>2010-07-29T04:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: cannot find sourcetype squid</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/cannot-find-sourcetype-squid/m-p/21509#M3206</link>
      <description>&lt;P&gt;thanks rroberts &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2010 22:05:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/cannot-find-sourcetype-squid/m-p/21509#M3206</guid>
      <dc:creator>njathan</dc:creator>
      <dc:date>2010-07-30T22:05:04Z</dc:date>
    </item>
  </channel>
</rss>

