AppD Archive

Collecting Query String Parameters

CommunityUser
Splunk Employee
Splunk Employee

It seems that there's no way to generically collect the query string parameters for a given http transaction snapshot.  Is there a reason for this?  I don't really want to spend time creating custom HttpCollectors for each of my transactions that have query string parameters.  It would be much easier if the default HttpCollector had an option to either just record everything after the ? in the url, or even better, parse out the individual parameters and store them separately.  Maybe there's a way to do this, and I'm just missing it.  Please let me know.

0 Karma
1 Solution

Arun_Dasetty
Super Champion

Hi,

We see aggressive seetings in Controller UI are disabled by default however you could just update default HTTP collector rule as below and you should see all query string HTTP parameters collected in snapshots for new load under "HTTP params" field in snapshot drilldown in UI.

image.png

Where we provided "HTTP parameter" column value as asterisk this helps to collect all http parameter for default HTTP collected which is by default associated to all BTs discovered.

Hope that information helps.

Regards,

Arun

View solution in original post

0 Karma

Arun_Dasetty
Super Champion

Hi,

We see aggressive seetings in Controller UI are disabled by default however you could just update default HTTP collector rule as below and you should see all query string HTTP parameters collected in snapshots for new load under "HTTP params" field in snapshot drilldown in UI.

image.png

Where we provided "HTTP parameter" column value as asterisk this helps to collect all http parameter for default HTTP collected which is by default associated to all BTs discovered.

Hope that information helps.

Regards,

Arun

0 Karma

Arun_Dasetty
Super Champion

Hi Mark,

Have you got chance to try the provided suggestions? Keep us posted how it goes after configuring suggested config

Regards,

Arun

0 Karma

CommunityUser
Splunk Employee
Splunk Employee

I didn't realize I had gotten a reply.  I received no email notification for the first reply, but just got one for this reply.  I just tried it.  This works better than I expected.  It contains cookies as well.  Is this documented somewhere?

Thanks,

Mark

0 Karma

Arun_Dasetty
Super Champion

Hi Mark,

The suggestion asterisk * wild card for HTTP parameter to collect all http parameters is not documented, regarding query on cookie you can refer doc link https://docs.appdynamics.com/display/PRO39/Configure+Data+Collectors , yes if you provide cookie name we will collect cookie name value details as well as part of snapshot data as we do for http parameters.

Hope that answers your query.

Regards,

Arun

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...