All Apps and Add-ons

How to add custom events to log data while searching for a log(With out mentioning it in the search)

pdantuuri0411
Explorer

How do I add custom events like loglevel that is mentioned in the log to be in an event so it can be categorized by choosing them. For example can I customize a field called loglevel where the type of loglevel can be filtered out?

.alt text

0 Karma

zonistj
Path Finder

It sounds like you want to do a field extraction for the log level. You can do this through the user interface by dropping down "Settings" then going to "Fields" then going to "Field Extractions" and using the wizard to create the extraction.

You can also do this through the props.conf file directly if you're familiar with that syntax.

https://docs.splunk.com/Documentation/Splunk/7.2.3/Knowledge/ExtractfieldsinteractivelywithIFX

https://docs.splunk.com/Splexicon:Fieldextraction

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...