All Apps and Add-ons

create custom source type

Edmondi
Explorer

I'm having trouble understanding how to create customer fields for my application logs. My logs have the following fields:

Timestamp SourceIP Token HTTP.Method URL Query.String Post.Data User.Agent

  • Delimiter is the TAB character.
  • I need to discard sourceIP in the indexing process.
  • The Token is a 24 characters string
  • Depending on the http method the Query.String and Post.Data are optional.

Can you please help me with a custom "pattern or regex" or "props.conf".

Thank you,
Edmond.

0 Karma
1 Solution

Edmondi
Explorer

Thanks Ayn.
I did see some general topic on other documents but this type of explanations I didn't find. If I will have further queries I will come back here :).

0 Karma

Edmondi
Explorer

Get method without query.string:

2013-07-20 10:56:54,188 62.75.10.167 tQxfxrcFuj=kdjxmxuq.R5ka GET /root/index.html Mozilla/5.0 (Linux; Android

Get method with query.string:

2013-07-20 10:57:14,764 62.75.10.167 tQxfxrcFu=Akdjxmx,qpR5ka GET /root/liquide.html language=en_US Mozilla/5.0 (Linux; Android

Post method:

2013-07-20 15:05:49,007 62.75.10.158 B52Je4k-XRCVPXm2JUzH8BZ3 POST /office/buy.html &tel_phone=123456789012&amount=123456&personal.token.name=personal.token&personal.token=ER6XEIF6JHLI620Y8KR3IZWSGF7IGCRZ Mozilla/5.0 (SymbianOS/9.2; U; Series60/3.1 NokiaE71-1

Thanks

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...