Hi,
I have a sever with splunk enterprise installed to monitor a directory containing <sample-filename>.gz files
Each file is of the below format and need to create a sourcetype that can
1. Ignore lines staring with //
2. Map the vales in [ ] to a standard header
----------------------------------------------------
[1599249608,75972,"sample@user.ca",638744076,1,861,337,3,"9","http",80,388951746,"http://abc.com",0,"","","","empty","Sample Filtering","","ctldl.windowsupdate.com","GET",21,3,126]
// random info here
// something something random
-------------------------------------------------------
Tried various strategies but filed. Looking for you help.
provide field header.