Getting Data In

Importing WebSphere - multiple SystemOut.log files

dr18
Explorer

So, at the moment, I want to import log files which were copied from the remote server to my Windows PC.

I want to import all of the proxy and AS logs and they all have the same SystemOut.log name.

What's the proper way to do that?  (I could rename each filename so that they are unique - but I'm sure there's a better way).   Searching the forum, I see some info regarding getting the live files, but not for an import.

 

Thanks!

Labels (1)

kennetkline
Path Finder

Ok,

Our websphere logs are in folder structure on linux:

I hope when you copied them you maintain the folder structure;

If you can get a UF inputs setup and pushed; I know it is easy;  not sure how much effort versus how many files to say is worthwhile.  If this is a routine task then probably work to setup a folder to allow drop and process.

c:\logs\host1\SystemOut.log
c:\logs\host2\SystemOut.log

etc.

If you have a UF and can get an INPUT setup:

The below c (1) \ logs (2) \ <folder> (3) is the hostname of the server.  Then would come in mapped to host name

[monitor://C:\logs\*\*.log]
source = websphere
host_segment = 3




0 Karma

dr18
Explorer

Thanks.

At the moment, I'm just trying to  learn the platform. I haven't gotten to UF yet.

 

So, in summary:  There needs to be something unique in the path to the filename.

 

It seems like the UI only allows you to select a file. As such, I've tested with zip-ping the path to the files and that works..  Is there another way of including the path, without first zipping it?

(The logfiles I have are inside zips with other files I don't want to index.. As such, I end up unzipping and re-zipping.)

 

Thanks!

 

 

0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...