All Apps and Add-ons

How to add web sphere logs into Splunk Websphere App

TimothyPeh
Engager

I am currently doing a POC where I want to index 1 websphere log file on my local host onto the Splunk app and see what kind of analysis can I do. However, I cannot find the option to upload to the app.

I can upload it generically to the search app but not to the Websphere App.

Tags (3)
0 Karma

okrabbe_splunk
Splunk Employee
Splunk Employee

If you just want to locally index one file you should be able to just set the index = websphere and as long as you did not rename the file it should automatically detect the sourcetype.

One thing I would recommend is to look at the file $SPLUNK_HOME/etc/apps/splunk_for_was/defaults/props.conf and take a look at how Splunk is determining sourcetypes. You will see it is matching source names and then setting a sourcetype. Further settings are then applied based on those sourcetypes. By having the correct index, sourcetypes, and field extractions this makes the dashboards in the WAS application work correctly.

If this is all very confusing to you I might recommend then taking a step back and reading through the install guide for the WAS application.

http://docs.splunk.com/Documentation/WAS/latest/InstallGuide/

Hope this helps.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...