All Apps and Add-ons
Highlighted

How to add custom events to log data while searching for a log(With out mentioning it in the search)

Explorer

How do I add custom events like loglevel that is mentioned in the log to be in an event so it can be categorized by choosing them. For example can I customize a field called loglevel where the type of loglevel can be filtered out?

.alt text

0 Karma
Highlighted

Re: How to add custom events to log data while searching for a log(With out mentioning it in the search)

Path Finder

It sounds like you want to do a field extraction for the log level. You can do this through the user interface by dropping down "Settings" then going to "Fields" then going to "Field Extractions" and using the wizard to create the extraction.

You can also do this through the props.conf file directly if you're familiar with that syntax.

https://docs.splunk.com/Documentation/Splunk/7.2.3/Knowledge/ExtractfieldsinteractivelywithIFX

https://docs.splunk.com/Splexicon:Fieldextraction

0 Karma