Getting Data In

Importing WebSphere - multiple SystemOut.log files

dr18
Explorer

So, at the moment, I want to import log files which were copied from the remote server to my Windows PC.

I want to import all of the proxy and AS logs and they all have the same SystemOut.log name.

What's the proper way to do that?  (I could rename each filename so that they are unique - but I'm sure there's a better way).   Searching the forum, I see some info regarding getting the live files, but not for an import.

 

Thanks!

Labels (1)

kennetkline
Path Finder

Ok,

Our websphere logs are in folder structure on linux:

I hope when you copied them you maintain the folder structure;

If you can get a UF inputs setup and pushed; I know it is easy;  not sure how much effort versus how many files to say is worthwhile.  If this is a routine task then probably work to setup a folder to allow drop and process.

c:\logs\host1\SystemOut.log
c:\logs\host2\SystemOut.log

etc.

If you have a UF and can get an INPUT setup:

The below c (1) \ logs (2) \ <folder> (3) is the hostname of the server.  Then would come in mapped to host name

[monitor://C:\logs\*\*.log]
source = websphere
host_segment = 3




0 Karma

dr18
Explorer

Thanks.

At the moment, I'm just trying to  learn the platform. I haven't gotten to UF yet.

 

So, in summary:  There needs to be something unique in the path to the filename.

 

It seems like the UI only allows you to select a file. As such, I've tested with zip-ping the path to the files and that works..  Is there another way of including the path, without first zipping it?

(The logfiles I have are inside zips with other files I don't want to index.. As such, I end up unzipping and re-zipping.)

 

Thanks!

 

 

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...