All Apps and Add-ons

How to add custom events to log data while searching for a log(With out mentioning it in the search)

pdantuuri0411
Explorer

How do I add custom events like loglevel that is mentioned in the log to be in an event so it can be categorized by choosing them. For example can I customize a field called loglevel where the type of loglevel can be filtered out?

.alt text

0 Karma

zonistj
Path Finder

It sounds like you want to do a field extraction for the log level. You can do this through the user interface by dropping down "Settings" then going to "Fields" then going to "Field Extractions" and using the wizard to create the extraction.

You can also do this through the props.conf file directly if you're familiar with that syntax.

https://docs.splunk.com/Documentation/Splunk/7.2.3/Knowledge/ExtractfieldsinteractivelywithIFX

https://docs.splunk.com/Splexicon:Fieldextraction

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...