All Apps and Add-ons

Why are field extractions failing for opendns:proxy sourcetype events?

Engager

Hi

I am splitting my umbrella DNS and proxy logs by sourcetype as per the instructions in the guide (opensdns:dnslogs, opendns:proxy).
However, the field extraction for the proxy logs is not working correctly.
DNS is working great and I can search by category, action, etc but these same field extractions fail for the opendns:proxy sourcetype events.

Am I missing something obvious?

1 Solution

Engager

I believe you may be using the incorrect sourcetype. The proxy logs need to use "opendns:proxylogs", it's referenced several times in the README with the proper sourcetype, but I see there is a typo that mentions "opendns:proxy". I will get this corrected in the README (I'm the owner/updater of this app via Hurricane Labs). Thanks for bringing this up!

View solution in original post

Engager

Updated the sourcetype to the correct format and all working correctly.

Thank you for the quick response!

0 Karma

Engager

I believe you may be using the incorrect sourcetype. The proxy logs need to use "opendns:proxylogs", it's referenced several times in the README with the proper sourcetype, but I see there is a typo that mentions "opendns:proxy". I will get this corrected in the README (I'm the owner/updater of this app via Hurricane Labs). Thanks for bringing this up!

View solution in original post

Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!