All Apps and Add-ons

What fields is the Splunk add-on for NetApp supposed to extract from syslog messages?

hettervi
Builder

Hi. The Splunk add-on for NetApp uses a transform to try to extract three fields from syslog; Thread, Event, and Message. The transform is not correct with the syslog I'm receiving, so I'll have to edit the regex manually. When I look at the NetApp documentation I can find no reference to the fields Thread and Event. Rather to me it looks like the extracted fields should be something like Identifier, Severity and Message.

Have a look at the NetApp documentation here: https://library.netapp.com/ecm/ecm_get_file/ecmlp2776519

Can someone explain to me what the three fields Thread, Event and Message should be?

0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...