<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: help with apache access searching in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/help-with-apache-access-searching/m-p/25422#M4801</link>
    <description>&lt;P&gt;im pretty sure my extractor (everything i posted in my original post) is not accurate. so i'm hoping you can provide the right regex/extractor that would solve my problem based on the log samples i provided. any ideas?&lt;/P&gt;</description>
    <pubDate>Wed, 07 Aug 2013 13:11:46 GMT</pubDate>
    <dc:creator>splunkmeuser</dc:creator>
    <dc:date>2013-08-07T13:11:46Z</dc:date>
    <item>
      <title>help with apache access searching</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-with-apache-access-searching/m-p/25416#M4795</link>
      <description>&lt;P&gt;LogFormat "%h %l %u %t %P \"%r\" %&amp;gt;s %X %b %I %O %D \"%{Referer}i\" \"%{User-Agent}i\" \"%{Host}i\" \"%{X-Forwarded-For}i\" \"%{X-Cluster-Client-IP}i\" \"%{True-Client-IP}i\" \"%{Via}i\" \"%{Akamai-Origin-Hop}i\"" combined&lt;/P&gt;

&lt;P&gt;what does the above translate to? &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;my attempt was (which i'm sure is very wrong):&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;^[[nspaces:clientip]]\s++[[nspaces:ident]]\s++[[nspaces:user]]\s++[[sbstring:req_time]]\s++[[nspaces:processid]]\s++[[access-request]]\s++[[nspaces:status]]\s++[[nspaces:connectionstatus]]\s++[[nspaces:bytes_received]]\s++[[nspaces:bytes_sent]]\s++[[nspaces:timeus]]\s++[[qstring:referrer]]\s++[[qstring:useragent]]\s++[[qstring:hservername]]\s++[[qstring:xforwardedfor]]\s++[[qstring:xclusterclientip]]\s++[[qstring:trueclientip]]\s++[[qstring:via]]\s++[[qstring:akamaiorigin]]&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:30:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-with-apache-access-searching/m-p/25416#M4795</guid>
      <dc:creator>splunkmeuser</dc:creator>
      <dc:date>2020-09-28T14:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: help with apache access searching</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-with-apache-access-searching/m-p/25417#M4796</link>
      <description>&lt;P&gt;What are you trying to achieve?  With a Splunk search you can simply search on field names as parameters (provided they are appropriately detected at index time, or you have defined a field extractor interactively).  I don't really understand what you mean by the use of the phrase "translates to".&lt;/P&gt;

&lt;P&gt;A typical search would be:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=weblogs clientip="75.41.6.*" status!=200 method=GET
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Nothing as complex as your regex.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2013 20:07:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-with-apache-access-searching/m-p/25417#M4796</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2013-08-05T20:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: help with apache access searching</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-with-apache-access-searching/m-p/25418#M4797</link>
      <description>&lt;P&gt;this is from the field extraction. i need to be able to make splunk recognize the custom format of my apache logs so that i can accurately get values from specific fields.  this is needed because i need to be generating reports on the values of those fields.  any help will be appreciated!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2013 21:40:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-with-apache-access-searching/m-p/25418#M4797</guid>
      <dc:creator>splunkmeuser</dc:creator>
      <dc:date>2013-08-05T21:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: help with apache access searching</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-with-apache-access-searching/m-p/25419#M4798</link>
      <description>&lt;P&gt;Rather than having to pore through the Apache logformat page to dissect your format string, it would be easier if you were to include a sample log line (suitably obsfuscated if need be provided you leave the general structure intact).&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2013 01:04:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-with-apache-access-searching/m-p/25419#M4798</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2013-08-06T01:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: help with apache access searching</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-with-apache-access-searching/m-p/25420#M4799</link>
      <description>&lt;P&gt;Here are two lines from my logs:&lt;/P&gt;

&lt;P&gt;10.50.1.1 - - [06/Aug/2013:12:20:07 -0400] 19537 "GET /fetch/ext/load.js HTTP/1.1" 200 + 5149 365 5310 4011 "&lt;A href="http://hs.garden.com/forum/load/appl/msg116.html" target="_blank"&gt;http://hs.garden.com/forum/load/appl/msg116.html&lt;/A&gt;" "Mozilla/5.0 (iPad; CPU OS 6_1_3 like Mac OS X) AppleWebKit/536.26 (KHTML, like Gecko) Version/6.0 Mobile/10B329 Safari/8536.25" "ss.lototo.com" "-" "-" "-" "-" "-"&lt;/P&gt;

&lt;P&gt;10.75.12.9 - - [06/Aug/2013:12:20:07 -0400] 19537 "GET /request/page/xml?path=%2Fcharlie-hunnam%2F1-k-42836&amp;amp;site==entertainment=0&amp;amp;is_xfinity= HTTP/1.1" 200 + 14891 414 15057 97443 "-" "-" "ss.lototo.com" "-" "-" "-" "-" "-"&lt;/P&gt;

&lt;P&gt;Please advise.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:30:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-with-apache-access-searching/m-p/25420#M4799</guid>
      <dc:creator>splunkmeuser</dc:creator>
      <dc:date>2020-09-28T14:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: help with apache access searching</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-with-apache-access-searching/m-p/25421#M4800</link>
      <description>&lt;P&gt;I see 20 fields in your example data and logformat definition, but only 19 in the extractor.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2013 03:18:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-with-apache-access-searching/m-p/25421#M4800</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2013-08-07T03:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: help with apache access searching</title>
      <link>https://community.splunk.com/t5/Splunk-Search/help-with-apache-access-searching/m-p/25422#M4801</link>
      <description>&lt;P&gt;im pretty sure my extractor (everything i posted in my original post) is not accurate. so i'm hoping you can provide the right regex/extractor that would solve my problem based on the log samples i provided. any ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2013 13:11:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/help-with-apache-access-searching/m-p/25422#M4801</guid>
      <dc:creator>splunkmeuser</dc:creator>
      <dc:date>2013-08-07T13:11:46Z</dc:date>
    </item>
  </channel>
</rss>

