All Apps and Add-ons

Field Extractions for IAS app

gregwilliams
Path Finder

Since I don't see much documentation for this app, what needs to be set in order for the lookups to happen? Do I need to change sourcetype, source?

0 Karma

southeringtonp
Motivator

The main thing is to make sure your sourcetype is set to ias.

0 Karma

southeringtonp
Motivator

Not sure I follow. Are you expecting to see a difference in the log entries themselves? The lookup values appear as new extracted fields, so you should start to see them in the field picker at the left. You might need to click pick fields to bring up the full list.

0 Karma

gregwilliams
Path Finder

got it. I still see default logs however. Do I need to put something else in my search string except for sourcetype=ias?

0 Karma

sdaniels
Splunk Employee
Splunk Employee
0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...