<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure '.out' files in inputs.conf? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-out-files-in-inputs-conf/m-p/158474#M32145</link>
    <description>&lt;P&gt;This is the .out file I tried to examine the file but i didn't able to understand anything. Please examine this and tell me what format should be given to the inputs.conf for .out files like this.&lt;/P&gt;</description>
    <pubDate>Mon, 10 Aug 2015 20:07:58 GMT</pubDate>
    <dc:creator>pavanae</dc:creator>
    <dc:date>2015-08-10T20:07:58Z</dc:date>
    <item>
      <title>How to configure '.out' files in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-out-files-in-inputs-conf/m-p/158471#M32142</link>
      <description>&lt;P&gt;Till now in our environment we have monitored only the log files which are in '.log' format in the Universal Forwarder Server as follows :- &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;In inputs.conf&lt;/EM&gt;&lt;/STRONG&gt; :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:/Home_DB/Oracle/webcenter/logs/sites.log]
index = cms_clb
sourcetype = log4j

[monitor:/Home_DB/Oracle/webcenter/logs/cas.log]
index = cms_clb
sourcetype = log4j
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Now as a part of the security requirement, we need to monitor a few more log files from the path &lt;CODE&gt;/Home_DB/Oracle/Middleware/user_projects/domains/webcenter/servers/webcenter-delivery1/logs/webcenter-delivery1.out&lt;/CODE&gt;, but here the logs were in &lt;CODE&gt;.out&lt;/CODE&gt; format. How do I add this path in inputs.conf and if added, what would be the source type for &lt;CODE&gt;.out&lt;/CODE&gt; format?&lt;BR /&gt;
Please help me out ASAP.&lt;/P&gt;

&lt;P&gt;Thanks in Advance.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2015 18:58:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-out-files-in-inputs-conf/m-p/158471#M32142</guid>
      <dc:creator>pavanae</dc:creator>
      <dc:date>2015-08-10T18:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure '.out' files in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-out-files-in-inputs-conf/m-p/158472#M32143</link>
      <description>&lt;P&gt;You'll need to examine the .out files or consult with dev/tech support to learn the source type.  Then add a new stanza to your inputs.conf file.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:/Home_DB/Oracle/Middleware/user_projects/domains/webcenter/servers/webcenter-delivery1/logs/webcenter-delivery1.out]
 index = cms_clb
 sourcetype = foo
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You may then need to modify props.conf to tell Splunk how to process the sourcetype.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2015 19:31:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-out-files-in-inputs-conf/m-p/158472#M32143</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-08-10T19:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure '.out' files in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-out-files-in-inputs-conf/m-p/158473#M32144</link>
      <description>&lt;P&gt;Jul 09, 2015 3:28:44 PM net.sf.ehcache.CacheManager addShutdownHookIfRequired&lt;BR /&gt;
INFO: The CacheManager shutdown hook is enabled because net.sf.ehcache.enableShutdownHook is set to true.&lt;BR /&gt;
Jul 09, 2015 3:28:44 PM net.sf.ehcache.CacheManager addShutdownHookIfRequired&lt;BR /&gt;
INFO: The CacheManager shutdown hook is enabled because net.sf.ehcache.enableShutdownHook is set to true.&lt;BR /&gt;
Jul 09, 2015 3:28:44 PM net.sf.ehcache.Cache createDiskStore&lt;BR /&gt;
INFO: **** Running custom ehcache jar using numOfDiskStores=10&lt;BR /&gt;
Jul 09, 2015 3:28:45 PM com.sun.jersey.server.impl.application.WebApplicationImpl initiate&lt;BR /&gt;
INFO: Initiating Jersey application, version 'Jersey: 1.1.4.1 11/24/2009 01:30 AM'&lt;BR /&gt;
Oracle WebCenter Sites 11gR1 11.1.1.8.0&lt;BR /&gt;
Copyright (c) 2011,2013, Oracle and/or its affiliates. All Rights Reserved.&lt;/P&gt;

&lt;P&gt;Oracle WebCenter Sites 11.1.1.8.0  Build Date: Jul 11 2014 at 15:16:48 Build Number: 35 Revision:165274&lt;/P&gt;

&lt;P&gt;Jul 09, 2015 3:28:46 PM net.sf.ehcache.CacheManager addShutdownHookIfRequired&lt;BR /&gt;
INFO: The CacheManager shutdown hook is enabled because net.sf.ehcache.enableShutdownHook is set to true.&lt;BR /&gt;
Oracle WebCenter Sites 11gR1 11.1.1.8.0&lt;BR /&gt;
Copyright (c) 2011,2013, Oracle and/or its affiliates. All Rights Reserved.&lt;/P&gt;

&lt;P&gt;Oracle WebCenter Sites |Satellite Server 11.1.1.8.0  Build Date: Jul 11 2014 at 15:16:48 Build Number: 35 Revision:165274&lt;/P&gt;

&lt;P&gt;Oracle WebCenter Sites 11gR1 11.1.1.8.0&lt;BR /&gt;
Copyright (c) 2011,2013, Oracle and/or its affiliates. All Rights Reserved.&lt;/P&gt;

&lt;P&gt;Oracle WebCenter Sites |Satellite Server 11.1.1.8.0  Build Date: Jul 11 2014 at 15:16:48 Build Number: 35 Revision:165274&lt;/P&gt;

&lt;P&gt;Oracle WebCenter Sites 11gR1 11.1.1.8.0&lt;BR /&gt;
Copyright (c) 2011,2013, Oracle and/or its affiliates. All Rights Reserved.&lt;/P&gt;

&lt;P&gt;Oracle WebCenter Sites |Satellite Server 11.1.1.8.0  Build Date: Jul 11 2014 at 15:16:48 Build Number: 35 Revision:165274&lt;/P&gt;

&lt;P&gt;2015-07-09 15:28:51,881 INFO [org.jasig.cas.services.DefaultServicesManagerImpl] - &lt;/P&gt;

&lt;HR /&gt;

&lt;H2&gt;GMS: address is 10.100.236.92:38365&lt;/H2&gt;

&lt;P&gt;2015-07-09 15:28:54,639 INFO [org.jasig.cas.util.AutowiringSchedulerFactoryBean] - &lt;BR /&gt;
2015-07-09 15:28:55,376 INFO [org.jasig.cas.web.flow.AuthenticationViaFormAction] - &lt;BR /&gt;
Jul 09, 2015 3:28:55 PM com.sun.jersey.spi.spring.container.servlet.SpringServlet getContext&lt;BR /&gt;
INFO: Using default applicationContext&lt;BR /&gt;
Jul 09, 2015 3:28:55 PM com.sun.jersey.spi.spring.container.SpringComponentProviderFactory register&lt;BR /&gt;
INFO: Registering Spring bean, TicketResource, of type com.fatwire.wem.sso.cas.integration.rest.TicketResource as a root resource class&lt;BR /&gt;
Jul 09, 2015 3:28:55 PM com.sun.jersey.spi.spring.container.SpringComponentProviderFactory register&lt;BR /&gt;
INFO: Registering Spring bean, TicketGrantingTicketResource, of type com.fatwire.wem.sso.cas.integration.rest.TicketGrantingTicketResource as a root resource class&lt;BR /&gt;
Jul 09, 2015 3:28:55 PM com.sun.jersey.server.impl.application.WebApplicationImpl initiate&lt;BR /&gt;
INFO: Initiating Jersey application, version 'Jersey: 1.1.4.1 11/24/2009 01:30 AM'&lt;/P&gt;

&lt;P&gt;2015-07-09 15:29:14,586 INFO [org.jasig.cas.ticket.registry.support.DefaultTicketRegistryCleaner] - &lt;BR /&gt;
2015-07-09 15:29:14,611 INFO [org.jasig.cas.ticket.registry.support.DefaultTicketRegistryCleaner] - &amp;lt;0 found to be removed.  Removing now.&amp;gt;&lt;BR /&gt;
2015-07-09 15:29:14,611 INFO [org.jasig.cas.ticket.registry.support.DefaultTicketRegistryCleaner] - &lt;BR /&gt;
Initializing MDCLoggingContext&lt;BR /&gt;
Initializing MDCLoggingContext&lt;BR /&gt;
Attempting to load ESAPI.properties via file I/O.&lt;BR /&gt;
Attempting to load ESAPI.properties as resource file via file I/O.&lt;BR /&gt;
Not found in 'org.owasp.esapi.resources' directory or file not readable: /AE/Oracle/Middleware/user_projects/domains/webcenter/ESAPI.properties&lt;BR /&gt;
Not found in SystemResource Directory/resourceDirectory: .esapi/ESAPI.properties&lt;BR /&gt;
Not found in 'user.home' (/home/weblogic) directory: /home/weblogic/esapi/ESAPI.properties&lt;BR /&gt;
Loading ESAPI.properties via file I/O failed. Exception was: java.io.FileNotFoundException&lt;BR /&gt;
Attempting to load ESAPI.properties via the classpath.&lt;BR /&gt;
SUCCESSFULLY LOADED ESAPI.properties via the CLASSPATH from '/ (root)' using current thread context class loader!&lt;BR /&gt;
Attempting to load validation.properties via file I/O.&lt;BR /&gt;
Attempting to load validation.properties as resource file via file I/O.&lt;BR /&gt;
Not found in 'org.owasp.esapi.resources' directory or file not readable: /AE/Oracle/Middleware/user_projects/domains/webcenter/validation.properties&lt;BR /&gt;
Not found in SystemResource Directory/resourceDirectory: .esapi/validation.properties&lt;BR /&gt;
Not found in 'user.home' (/home/weblogic) directory: /home/weblogic/esapi/validation.properties&lt;BR /&gt;
Loading validation.properties via file I/O failed.&lt;BR /&gt;
Attempting to load validation.properties via the classpath.&lt;BR /&gt;
SUCCESSFULLY LOADED validation.properties via the CLASSPATH from '/ (root)' using current thread context class loader!&lt;BR /&gt;
Attempting to load antisamy-esapi.xml as resource file via file I/O.&lt;BR /&gt;
Not found in 'org.owasp.esapi.resources' directory or file not readable: /AE/Oracle/Middleware/user_projects/domains/webcenter/antisamy-esapi.xml&lt;BR /&gt;
Not found in SystemResource Directory/resourceDirectory: .esapi/antisamy-esapi.xml&lt;BR /&gt;
Not found in 'user.home' (/home/weblogic) directory: /home/weblogic/esapi/antisamy-esapi.xml&lt;BR /&gt;
2015-07-09 15:30:54,587 INFO [org.jasig.cas.services.DefaultServicesManagerImpl] - &lt;BR /&gt;
2015-07-09 15:30:54,588 INFO [org.jasig.cas.services.DefaultServicesManagerImpl] - &lt;BR /&gt;
2015-07-09 15:32:54,580 INFO [org.jasig.cas.services.DefaultServicesManagerImpl] - &lt;BR /&gt;
2015-07-09 15:32:54,580 INFO [org.jasig.cas.services.DefaultServicesManagerImpl] - &lt;BR /&gt;
2015-07-09 15:34:54,580 INFO [org.jasig.cas.services.DefaultServicesManagerImpl] - &lt;BR /&gt;
2015-07-09 15:34:54,581 INFO [org.jasig.cas.services.DefaultServicesManagerImpl] - &lt;/P&gt;

&lt;P&gt;2015-07-09 15:35:56,608 INFO [org.jasig.cas.util.AutowiringSchedulerFactoryBean] - &lt;BR /&gt;
2015-07-09 15:35:56,611 INFO [org.jasig.cas.util.JBossCacheFactoryBean] - &lt;BR /&gt;
log4j:WARN No appenders could be found for logger (com.fatwire.logging.cs.cache.ehcache).&lt;BR /&gt;
log4j:WARN Please initialize the log4j system properly.&lt;BR /&gt;
log4j:WARN See &lt;A href="http://logging.apache.org/log4j/1.2/faq.html#noconfig" target="_blank"&gt;http://logging.apache.org/log4j/1.2/faq.html#noconfig&lt;/A&gt; for more info.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 06:54:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-out-files-in-inputs-conf/m-p/158473#M32144</guid>
      <dc:creator>pavanae</dc:creator>
      <dc:date>2020-09-29T06:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure '.out' files in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-out-files-in-inputs-conf/m-p/158474#M32145</link>
      <description>&lt;P&gt;This is the .out file I tried to examine the file but i didn't able to understand anything. Please examine this and tell me what format should be given to the inputs.conf for .out files like this.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2015 20:07:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-out-files-in-inputs-conf/m-p/158474#M32145</guid>
      <dc:creator>pavanae</dc:creator>
      <dc:date>2015-08-10T20:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure '.out' files in inputs.conf?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-out-files-in-inputs-conf/m-p/158475#M32146</link>
      <description>&lt;P&gt;That's quite a collection of styles.  I suggest indexing it as plain text.  Splunk will interpret most of the timestamps and assign timestamps to those lines that don't have one.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2015 20:15:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-out-files-in-inputs-conf/m-p/158475#M32146</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-08-10T20:15:02Z</dc:date>
    </item>
  </channel>
</rss>

