<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FIX message protocol with Splunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/FIX-message-protocol-with-Splunk/m-p/39100#M178756</link>
    <description>&lt;P&gt;I've installed FIX Log Parsing by Glenn but am not having much joy: &lt;/P&gt;

&lt;P&gt;20/05/2013 10:19:37.826  2013-05-20 10:19:37,826 INFO  in.GSFUT_FILCRD - &amp;lt;231 ExecutionReport (8=FIX.4.2\x19=330\x135=8\x149=GSFUT\x156=FILCRD\x1142=FUSNYQAC\x157=A396051\x134=231\x152=20130520-09:19:37\x137=FUSNYQAC15120130516\x111=10301529\x141=10301523\x117=F5193780920130520\x120=0\x1150=4\x139=4\x11=C0795408\x163=0\x155=HCK3\x148=HCEIK3\x122=5\x1167=FUT\x1200=201305\x154=1\x138=13\x140=1\x115=HKD\x159=0\x147=A\x132=0\x131=0\x130=XHKF\x1151=0\x114=0\x16=0\x175=20130516\x160=20130520-09:19:37\x1120=HKD\x121=3\x110=255\x1)&lt;/P&gt;</description>
    <pubDate>Mon, 20 May 2013 12:56:02 GMT</pubDate>
    <dc:creator>nathanlhopkins</dc:creator>
    <dc:date>2013-05-20T12:56:02Z</dc:date>
    <item>
      <title>FIX message protocol with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/FIX-message-protocol-with-Splunk/m-p/39098#M178754</link>
      <description>&lt;P&gt;Does anyone have any recommendations of how to use Splunk with FIX trading messages logs and in particular is there anything that understand's / translates FIX tags?&lt;/P&gt;</description>
      <pubDate>Sun, 19 May 2013 21:39:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/FIX-message-protocol-with-Splunk/m-p/39098#M178754</guid>
      <dc:creator>nathanlhopkins</dc:creator>
      <dc:date>2013-05-19T21:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: FIX message protocol with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/FIX-message-protocol-with-Splunk/m-p/39099#M178755</link>
      <description>&lt;P&gt;Some prior responses to the same general question, and there's apparently an app for that:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/3000/using-delims-to-extract-fix-data"&gt;http://splunk-base.splunk.com/answers/3000/using-delims-to-extract-fix-data&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/answers/887/has-anyone-got-a-method-for-decoding-fix-financial-format-logs"&gt;http://splunk-base.splunk.com/answers/887/has-anyone-got-a-method-for-decoding-fix-financial-format-logs&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/apps/22347/financial-information-exchange-fix-log-parsing"&gt;http://splunk-base.splunk.com/apps/22347/financial-information-exchange-fix-log-parsing&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 19 May 2013 23:07:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/FIX-message-protocol-with-Splunk/m-p/39099#M178755</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2013-05-19T23:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: FIX message protocol with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/FIX-message-protocol-with-Splunk/m-p/39100#M178756</link>
      <description>&lt;P&gt;I've installed FIX Log Parsing by Glenn but am not having much joy: &lt;/P&gt;

&lt;P&gt;20/05/2013 10:19:37.826  2013-05-20 10:19:37,826 INFO  in.GSFUT_FILCRD - &amp;lt;231 ExecutionReport (8=FIX.4.2\x19=330\x135=8\x149=GSFUT\x156=FILCRD\x1142=FUSNYQAC\x157=A396051\x134=231\x152=20130520-09:19:37\x137=FUSNYQAC15120130516\x111=10301529\x141=10301523\x117=F5193780920130520\x120=0\x1150=4\x139=4\x11=C0795408\x163=0\x155=HCK3\x148=HCEIK3\x122=5\x1167=FUT\x1200=201305\x154=1\x138=13\x140=1\x115=HKD\x159=0\x147=A\x132=0\x131=0\x130=XHKF\x1151=0\x114=0\x16=0\x175=20130516\x160=20130520-09:19:37\x1120=HKD\x121=3\x110=255\x1)&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2013 12:56:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/FIX-message-protocol-with-Splunk/m-p/39100#M178756</guid>
      <dc:creator>nathanlhopkins</dc:creator>
      <dc:date>2013-05-20T12:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: FIX message protocol with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/FIX-message-protocol-with-Splunk/m-p/39101#M178757</link>
      <description>&lt;P&gt;Within seach I believe I should just be able to run:&lt;/P&gt;

&lt;P&gt;index=test_index Execution* 10:19:37 826 | translatefix&lt;/P&gt;

&lt;P&gt;To convert the above into readable tagged format?&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2013 12:56:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/FIX-message-protocol-with-Splunk/m-p/39101#M178757</guid>
      <dc:creator>nathanlhopkins</dc:creator>
      <dc:date>2013-05-20T12:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: FIX message protocol with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/FIX-message-protocol-with-Splunk/m-p/39102#M178758</link>
      <description>&lt;P&gt;Found the issue with FIX Log Parser: it turned out to be missing values after the stanza in commands.conf;&lt;/P&gt;

&lt;P&gt;[translatefix]&lt;BR /&gt;
filename = translatefix.py&lt;BR /&gt;
streaming = true&lt;BR /&gt;
enableheader = false&lt;BR /&gt;
retainsevents = true&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2013 13:46:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/FIX-message-protocol-with-Splunk/m-p/39102#M178758</guid>
      <dc:creator>nathanlhopkins</dc:creator>
      <dc:date>2013-05-20T13:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: FIX message protocol with Splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/FIX-message-protocol-with-Splunk/m-p/39103#M178759</link>
      <description>&lt;P&gt;I'm using translatefix too.  To set your expectations: In my experience, the translated fields are not subsequently extracted and indexed. For example, I can search "MsgType=Execution" as a string, but I can't search "MsgType!=Heartbeat" because it's not extracted as a key/value pair.  I discussed it with a Splunk Sales Engineer, he had a trick to dump the translated fields back into the raw index (?) but I've lost the notes I took that day (arrrgh!)..  I've not had the time or talent to revisit the problem, but I would be grateful for anybody who could.&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2013 17:36:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/FIX-message-protocol-with-Splunk/m-p/39103#M178759</guid>
      <dc:creator>anewell</dc:creator>
      <dc:date>2013-05-20T17:36:29Z</dc:date>
    </item>
  </channel>
</rss>

