All Apps and Add-ons

How to add custom events to log data while searching for a log(With out mentioning it in the search)

pdantuuri0411
Explorer

How do I add custom events like loglevel that is mentioned in the log to be in an event so it can be categorized by choosing them. For example can I customize a field called loglevel where the type of loglevel can be filtered out?

.alt text

0 Karma

zonistj
Path Finder

It sounds like you want to do a field extraction for the log level. You can do this through the user interface by dropping down "Settings" then going to "Fields" then going to "Field Extractions" and using the wizard to create the extraction.

You can also do this through the props.conf file directly if you're familiar with that syntax.

https://docs.splunk.com/Documentation/Splunk/7.2.3/Knowledge/ExtractfieldsinteractivelywithIFX

https://docs.splunk.com/Splexicon:Fieldextraction

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...