AppD Archive

Collecting Query String Parameters

CommunityUser
Splunk Employee
Splunk Employee

It seems that there's no way to generically collect the query string parameters for a given http transaction snapshot.  Is there a reason for this?  I don't really want to spend time creating custom HttpCollectors for each of my transactions that have query string parameters.  It would be much easier if the default HttpCollector had an option to either just record everything after the ? in the url, or even better, parse out the individual parameters and store them separately.  Maybe there's a way to do this, and I'm just missing it.  Please let me know.

0 Karma
1 Solution

Arun_Dasetty
Super Champion

Hi,

We see aggressive seetings in Controller UI are disabled by default however you could just update default HTTP collector rule as below and you should see all query string HTTP parameters collected in snapshots for new load under "HTTP params" field in snapshot drilldown in UI.

image.png

Where we provided "HTTP parameter" column value as asterisk this helps to collect all http parameter for default HTTP collected which is by default associated to all BTs discovered.

Hope that information helps.

Regards,

Arun

View solution in original post

0 Karma

Arun_Dasetty
Super Champion

Hi,

We see aggressive seetings in Controller UI are disabled by default however you could just update default HTTP collector rule as below and you should see all query string HTTP parameters collected in snapshots for new load under "HTTP params" field in snapshot drilldown in UI.

image.png

Where we provided "HTTP parameter" column value as asterisk this helps to collect all http parameter for default HTTP collected which is by default associated to all BTs discovered.

Hope that information helps.

Regards,

Arun

0 Karma

Arun_Dasetty
Super Champion

Hi Mark,

Have you got chance to try the provided suggestions? Keep us posted how it goes after configuring suggested config

Regards,

Arun

0 Karma

CommunityUser
Splunk Employee
Splunk Employee

I didn't realize I had gotten a reply.  I received no email notification for the first reply, but just got one for this reply.  I just tried it.  This works better than I expected.  It contains cookies as well.  Is this documented somewhere?

Thanks,

Mark

0 Karma

Arun_Dasetty
Super Champion

Hi Mark,

The suggestion asterisk * wild card for HTTP parameter to collect all http parameters is not documented, regarding query on cookie you can refer doc link https://docs.appdynamics.com/display/PRO39/Configure+Data+Collectors , yes if you provide cookie name we will collect cookie name value details as well as part of snapshot data as we do for http parameters.

Hope that answers your query.

Regards,

Arun

0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...