All Apps and Add-ons

Unable to find source type for squid logs

garykremmer
Engager

I am using Splunk version 6.0.2-196940

When I add a local file source /var/log/squid3/access.log I don't see any option of selecting squid as source type. Automatic source type detection is also failing.

I also installed Splunk Weblog Add-on and Splunk for Squid apps but still can't find source type for squid.

How do I go about solving this?

Tags (1)

Ayn
Legend

Use the "manual" option where you choose sourcetype in the web interface and specify "squid" yourself.

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!