<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: teach splunk to read data from log in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/teach-splunk-to-read-data-from-log/m-p/88801#M22736</link>
    <description>&lt;P&gt;IFX works quite well, for me, but if it seems to be failing for you and you are unable to define the regex correctly through it, you could use a custom made regex and use the props.conf way of extracting fields. This is also very well documented at:
&lt;A href="http://www.splunk.com/base/Documentation/4.1.5/Knowledge/Createandmaintainsearch-timefieldextractionsthroughconfigurationfiles" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.5/Knowledge/Createandmaintainsearch-timefieldextractionsthroughconfigurationfiles&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Nov 2010 08:28:29 GMT</pubDate>
    <dc:creator>Genti</dc:creator>
    <dc:date>2010-11-16T08:28:29Z</dc:date>
    <item>
      <title>teach splunk to read data from log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/teach-splunk-to-read-data-from-log/m-p/88799#M22734</link>
      <description>&lt;P&gt;I have syslog from a server sending me logs from /var/log/secure (ssh). But splunk can't seem to read out some stuff from it (ex src)&lt;/P&gt;

&lt;P&gt;The packet looks like this. &lt;/P&gt;

&lt;P&gt;Nov 14 21:50:33 172.28.2.5 sshd[984]: Accepted password for apa from 192.168.1.5 port 42957 ssh2
tag::host=test   Options|  host=192.168.1.1 Wiki   Options&lt;/P&gt;

&lt;P&gt;I want the src (192.168.1.5) to appear in the "src" column.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2010 05:04:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/teach-splunk-to-read-data-from-log/m-p/88799#M22734</guid>
      <dc:creator>fisk12</dc:creator>
      <dc:date>2010-11-15T05:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: teach splunk to read data from log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/teach-splunk-to-read-data-from-log/m-p/88800#M22735</link>
      <description>&lt;P&gt;Sounds like you want to do some field extraction.  You can give Splunk the field values and then give the results a field name.  This is well documented and can be found at:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.splunk.com/base/Documentation/4.1.5/User/InteractiveFieldExtractionExample" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.5/User/InteractiveFieldExtractionExample&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2010 21:26:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/teach-splunk-to-read-data-from-log/m-p/88800#M22735</guid>
      <dc:creator>treinke</dc:creator>
      <dc:date>2010-11-15T21:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: teach splunk to read data from log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/teach-splunk-to-read-data-from-log/m-p/88801#M22736</link>
      <description>&lt;P&gt;IFX works quite well, for me, but if it seems to be failing for you and you are unable to define the regex correctly through it, you could use a custom made regex and use the props.conf way of extracting fields. This is also very well documented at:
&lt;A href="http://www.splunk.com/base/Documentation/4.1.5/Knowledge/Createandmaintainsearch-timefieldextractionsthroughconfigurationfiles" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.1.5/Knowledge/Createandmaintainsearch-timefieldextractionsthroughconfigurationfiles&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2010 08:28:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/teach-splunk-to-read-data-from-log/m-p/88801#M22736</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2010-11-16T08:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: teach splunk to read data from log</title>
      <link>https://community.splunk.com/t5/Splunk-Search/teach-splunk-to-read-data-from-log/m-p/88802#M22737</link>
      <description>&lt;P&gt;Hmm, but say that i monitor all events in a 15 minutes interval, i have some stuff from the firewall that shows up in the "src" field. I also log some stuff from one of the linux server, and i want it to be able to show the source of the ssh stuff (or from the apache server) in the same "src" field as the firewall.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2010 23:41:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/teach-splunk-to-read-data-from-log/m-p/88802#M22737</guid>
      <dc:creator>fisk12</dc:creator>
      <dc:date>2010-11-19T23:41:27Z</dc:date>
    </item>
  </channel>
</rss>

