All Apps and Add-ons

Why are field extractions failing for opendns:proxy sourcetype events?

Engager

Hi

I am splitting my umbrella DNS and proxy logs by sourcetype as per the instructions in the guide (opensdns:dnslogs, opendns:proxy).
However, the field extraction for the proxy logs is not working correctly.
DNS is working great and I can search by category, action, etc but these same field extractions fail for the opendns:proxy sourcetype events.

Am I missing something obvious?

1 Solution

Engager

I believe you may be using the incorrect sourcetype. The proxy logs need to use "opendns:proxylogs", it's referenced several times in the README with the proper sourcetype, but I see there is a typo that mentions "opendns:proxy". I will get this corrected in the README (I'm the owner/updater of this app via Hurricane Labs). Thanks for bringing this up!

View solution in original post

Engager

Updated the sourcetype to the correct format and all working correctly.

Thank you for the quick response!

0 Karma

Engager

I believe you may be using the incorrect sourcetype. The proxy logs need to use "opendns:proxylogs", it's referenced several times in the README with the proper sourcetype, but I see there is a typo that mentions "opendns:proxy". I will get this corrected in the README (I'm the owner/updater of this app via Hurricane Labs). Thanks for bringing this up!

View solution in original post

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!