All Apps and Add-ons

Unable to find source type for squid logs


I am using Splunk version 6.0.2-196940

When I add a local file source /var/log/squid3/access.log I don't see any option of selecting squid as source type. Automatic source type detection is also failing.

I also installed Splunk Weblog Add-on and Splunk for Squid apps but still can't find source type for squid.

How do I go about solving this?

Tags (1)


Use the "manual" option where you choose sourcetype in the web interface and specify "squid" yourself.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!